Back

CRITICAL

HTTP/2 server push UAF

Published Sep 6, 2026

Description

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

Affected products

Remediation

Red Hat statement

This flaw is rated as Low impact. It affects libcurl when configured to use HTTP/2 Server Push with shared connections, a non-default and less common deployment scenario in Red Hat products. Successful exploitation would lead to a use-after-free condition during resource cleanup, primarily impacting service availability.

Red Hat mitigation

Disable HTTP/2 Server Push (CURLMOPT_PUSHFUNCTION) and shared connection handles (CURL_LOCK_DATA_CONNECT) in libcurl clients to eliminate the vulnerable code path. If these features cannot be disabled, enforce host-based firewalls to restrict affected applications' outbound HTTPS traffic solely to trusted endpoints, neutralizing the risk of exploitation by malicious HTTP/2 servers.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner curl
Published Sep 6, 2026
Updated Sep 15, 2026
Reserved Aug 5, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Modified
Modified Sep 15, 2026
Red Hat
Severity Low
Public date Sep 6, 2026