CVE-2026-80229
Dashboard / Vulnerabilities / CVE-2026-80229
CVE-2026-80229
Summary: OpenSSL provider use-after-free
Details: When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations.
References: https://curl.se/docs/CVE-2026-80229.html, https://curl.se/docs/CVE-2026-80229.json, https://hackerone.com/reports/3969255, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80229.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80229, https://github.com/curl/curl.git
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
