CVE-2026-10536: HTTP/2 stream-dependency tree UAF
A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via CURLOPTSTREAMDEPENDS or CURLOPTSTREAMDEPENDSE, subsequently invokes curleasyreset(), and finally terminates the handle with curleasycleanup(). During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/curlto a version that resolves this vulnerability.Fixed in 8.21.0-2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.11.1-10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10536?
CVE-2026-10536 has a risk rating of 28, indicating a moderate severity level.
How do I fix CVE-2026-10536?
To fix CVE-2026-10536, ensure you update libcurl to the latest version that includes the patch addressing this vulnerability.
What software is affected by CVE-2026-10536?
CVE-2026-10536 affects the libcurl software library.
What is the nature of the vulnerability in CVE-2026-10536?
CVE-2026-10536 is a use-after-free vulnerability that occurs when manipulating an HTTP/2 stream-dependency tree.
When was CVE-2026-10536 published?
CVE-2026-10536 was published on July 3, 2026.