HTTP/2 server push UAF
Published Sep 6, 2026
9.1
CRITICALCVSS 3.1
EPSS 0.58%
Description
A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.
Affected products
-
- Version 7.44.0StatusaffectedConstraints<8.14.2
- Version 7.44.0StatusaffectedConstraints-
- Version 7.45.0StatusaffectedConstraints-
- Version 7.46.0StatusaffectedConstraints-
- Version 7.47.0StatusaffectedConstraints-
- Version 7.47.1StatusaffectedConstraints-
- Version 7.48.0StatusaffectedConstraints-
- Version 7.49.0StatusaffectedConstraints-
- Version 7.49.1StatusaffectedConstraints-
- Version 7.50.0StatusaffectedConstraints-
- Version 7.50.1StatusaffectedConstraints-
- Version 7.50.2StatusaffectedConstraints-
- Version 7.50.3StatusaffectedConstraints-
- Version 7.51.0StatusaffectedConstraints-
- Version 7.52.0StatusaffectedConstraints-
- Version 7.52.1StatusaffectedConstraints-
- Version 7.53.0StatusaffectedConstraints-
- Version 7.53.1StatusaffectedConstraints-
- Version 7.54.0StatusaffectedConstraints-
- Version 7.54.1StatusaffectedConstraints-
- Version 7.55.0StatusaffectedConstraints-
- Version 7.55.1StatusaffectedConstraints-
- Version 7.56.0StatusaffectedConstraints-
- Version 7.56.1StatusaffectedConstraints-
- Version 7.57.0StatusaffectedConstraints-
- Version 7.58.0StatusaffectedConstraints-
- Version 7.59.0StatusaffectedConstraints-
- Version 7.60.0StatusaffectedConstraints-
- Version 7.61.0StatusaffectedConstraints-
- Version 7.61.1StatusaffectedConstraints-
- Version 7.62.0StatusaffectedConstraints-
- Version 7.63.0StatusaffectedConstraints-
- Version 7.64.0StatusaffectedConstraints-
- Version 7.64.1StatusaffectedConstraints-
- Version 7.65.0StatusaffectedConstraints-
- Version 7.65.1StatusaffectedConstraints-
- Version 7.65.2StatusaffectedConstraints-
- Version 7.65.3StatusaffectedConstraints-
- Version 7.66.0StatusaffectedConstraints-
- Version 7.67.0StatusaffectedConstraints-
- Version 7.68.0StatusaffectedConstraints-
- Version 7.69.0StatusaffectedConstraints-
- Version 7.69.1StatusaffectedConstraints-
- Version 7.70.0StatusaffectedConstraints-
- Version 7.71.0StatusaffectedConstraints-
- Version 7.71.1StatusaffectedConstraints-
- Version 7.72.0StatusaffectedConstraints-
- Version 7.73.0StatusaffectedConstraints-
- Version 7.74.0StatusaffectedConstraints-
- Version 7.75.0StatusaffectedConstraints-
- Version 7.76.0StatusaffectedConstraints-
- Version 7.76.1StatusaffectedConstraints-
- Version 7.77.0StatusaffectedConstraints-
- Version 7.78.0StatusaffectedConstraints-
- Version 7.79.0StatusaffectedConstraints-
- Version 7.79.1StatusaffectedConstraints-
- Version 7.80.0StatusaffectedConstraints-
- Version 7.81.0StatusaffectedConstraints-
- Version 7.82.0StatusaffectedConstraints-
- Version 7.83.0StatusaffectedConstraints-
- Version 7.83.1StatusaffectedConstraints-
- Version 7.84.0StatusaffectedConstraints-
- Version 7.85.0StatusaffectedConstraints-
- Version 7.86.0StatusaffectedConstraints-
- Version 7.87.0StatusaffectedConstraints-
- Version 7.88.0StatusaffectedConstraints-
- Version 7.88.1StatusaffectedConstraints-
- Version 8.0.0StatusaffectedConstraints-
- Version 8.0.1StatusaffectedConstraints-
- Version 8.1.0StatusaffectedConstraints-
- Version 8.1.1StatusaffectedConstraints-
- Version 8.1.2StatusaffectedConstraints-
- Version 8.10.0StatusaffectedConstraints-
- Version 8.10.1StatusaffectedConstraints-
- Version 8.11.0StatusaffectedConstraints-
- Version 8.11.1StatusaffectedConstraints-
- Version 8.12.0StatusaffectedConstraints-
- Version 8.12.1StatusaffectedConstraints-
- Version 8.13.0StatusaffectedConstraints-
- Version 8.14.0StatusaffectedConstraints-
- Version 8.14.1StatusaffectedConstraints-
- Version 8.15.0StatusaffectedConstraints<8.16.1
- Version 8.15.0StatusaffectedConstraints-
- Version 8.16.0StatusaffectedConstraints-
- Version 8.17.0StatusaffectedConstraints<8.20.1
- Version 8.17.0StatusaffectedConstraints-
- Version 8.18.0StatusaffectedConstraints-
- Version 8.19.0StatusaffectedConstraints-
- Version 8.2.0StatusaffectedConstraints-
- Version 8.2.1StatusaffectedConstraints-
- Version 8.20.0StatusaffectedConstraints-
- Version 8.21.0StatusaffectedConstraints<8.22.0
- Version 8.21.0StatusaffectedConstraints-
- Version 8.3.0StatusaffectedConstraints-
- Version 8.4.0StatusaffectedConstraints-
- Version 8.5.0StatusaffectedConstraints-
- Version 8.6.0StatusaffectedConstraints-
- Version 8.7.0StatusaffectedConstraints-
- Version 8.7.1StatusaffectedConstraints-
- Version 8.8.0StatusaffectedConstraints-
- Version 8.9.0StatusaffectedConstraints-
- Version 8.9.1StatusaffectedConstraints-
- Version
-
- Version StatusaffectedConstraints
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Curl | Curl | unaffected |
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Curl | Curl | unaffected |
|
No data.
Red Hat Hardened Images
curl-main-8.22.0-0.1.hum1
Fixed · RHSA-2026:63161
Red Hat Hardened Images
rust-main-1.98.0-1.hum1
Fixed · RHSA-2026:63514
Confidential Compute Attestation
build-of-trustee/trustee-rhel9
Fix deferred
Confidential Compute Attestation
openshift-sandboxed-containers/osc-podvm-payload-rhel9
Fix deferred
Red Hat Enterprise Linux 10
curl
Fix deferred
Red Hat Enterprise Linux 10
igvm
Fix deferred
Red Hat Enterprise Linux 10
rust
Fix deferred
Red Hat Enterprise Linux 10
s390utils
Fix deferred
Red Hat Enterprise Linux 10
snphost
Fix deferred
Red Hat Enterprise Linux 10
trustee
Fix deferred
Red Hat Enterprise Linux 6
curl
Not affected
Red Hat Enterprise Linux 7
curl
Not affected
Red Hat Enterprise Linux 8
curl
Fix deferred
Red Hat Enterprise Linux 9
curl
Affected
Red Hat Enterprise Linux 9
rust
Fix deferred
Red Hat Enterprise Linux 9
snphost
Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3
rust
Fix deferred
Red Hat Hardened Images
openshell
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/code-rhel9
Fix deferred
Red Hat Satellite 6
foreman
Not affected
Red Hat Satellite 6
openvox-agent
Fix deferred
Red Hat Satellite 6
puppet-agent
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | curl-main-8.22.0-0.1.hum1 | Fixed | RHSA-2026:63161 |
| Red Hat Hardened Images | rust-main-1.98.0-1.hum1 | Fixed | RHSA-2026:63514 |
| Confidential Compute Attestation | build-of-trustee/trustee-rhel9 | Fix deferred | n/a |
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | curl | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | igvm | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | rust | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | s390utils | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | snphost | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | trustee | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | curl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | curl | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | curl | Affected | n/a |
| Red Hat Enterprise Linux 9 | rust | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | snphost | Fix deferred | n/a |
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rust | Fix deferred | n/a |
| Red Hat Hardened Images | openshell | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/code-rhel9 | Fix deferred | n/a |
| Red Hat Satellite 6 | foreman | Not affected | n/a |
| Red Hat Satellite 6 | openvox-agent | Fix deferred | n/a |
| Red Hat Satellite 6 | puppet-agent | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is rated as Low impact. It affects libcurl when configured to use HTTP/2 Server Push with shared connections, a non-default and less common deployment scenario in Red Hat products. Successful exploitation would lead to a use-after-free condition during resource cleanup, primarily impacting service availability.
Red Hat mitigation
Disable HTTP/2 Server Push (CURLMOPT_PUSHFUNCTION) and shared connection handles (CURL_LOCK_DATA_CONNECT) in libcurl clients to eliminate the vulnerable code path. If these features cannot be disabled, enforce host-based firewalls to restrict affected applications' outbound HTTPS traffic solely to trusted endpoints, neutralizing the risk of exploitation by malicious HTTP/2 servers.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 8, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Sep–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.58% (0.00584) | 45.93th | v5 (v2026.06.15) |
| Sep 7, 2026 | 0.21% (0.00206) | 10.74th | v5 (v2026.06.15) |
References (7)
- https://access.redhat.com/security/cve/CVE-2026-18924 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2529201 Issue Tracking
- https://curl.se/docs/CVE-2026-18924.html PatchVendor Advisory
- https://curl.se/docs/CVE-2026-18924.json Vendor Advisory
- https://hackerone.com/reports/3916059 exploitMitigationThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-18924
- https://www.cve.org/CVERecord?id=CVE-2026-18924
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-18924 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2529201 | Issue Tracking | |
| https://curl.se/docs/CVE-2026-18924.html | PatchVendor Advisory | |
| https://curl.se/docs/CVE-2026-18924.json | Vendor Advisory | |
| https://hackerone.com/reports/3916059 | exploitMitigationThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-18924 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-18924 |
Change history (0)
No recorded changes yet.