GHSA-xcm8-9xjx-f5jqCriticalCVSS 9.1

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to...

Published
September 6, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

🔗 References (5)