Sploitus

CVE-2026-10536

No indexed exploits for CVE-2026-10536 yet

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

Affected products
Ibm Aix, Linuxmint, Ubuntu, Libcurl
Haxx Curl
< 8.21.0
CVSS 3.1
9.8 CRITICAL
EPSS
0.5% (41th percentile)
Weakness
CWE-416
NVD status
Analyzed
Published
2026-07-03
CVE-2026-10536 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-10536 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-10536 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.