CVE-2026-9080
EUVD-2026-4151103.07.2026, 07:16
Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| curl | curl | 𝑥 ≤ 8.20.0 | CNA |
| curl | curl | 𝑥 ≤ 8.19.0 | CNA |
| curl | curl | 𝑥 ≤ 8.18.0 | CNA |
| curl | curl | 𝑥 ≤ 8.17.0 | CNA |
| curl | curl | 𝑥 ≤ 8.16.0 | CNA |
| curl | curl | 𝑥 ≤ 8.15.0 | CNA |
| curl | curl | 𝑥 ≤ 8.14.1 | CNA |
| curl | curl | 𝑥 ≤ 8.14.0 | CNA |
| curl | curl | 𝑥 ≤ 8.13.0 | CNA |
Debian Releases
Vulnerability Media Exposure