Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80229— OpenSSL provider use-after-free

Quick assessment

Affected
curl curl
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 8.21.0版本、8.20.0版本、8.19.0版本、8.18.0版本、8.17.0版本、8.16.0版本、8.15.0版本、8.14.1版本和8.14.0版本存在资源管理错误漏洞,该漏洞源于通过libcurl的multi接口执行传输时,在OpenSSL 3 provider配置下,libcurl将已分配的库上下文附加到easy handle状态并传递给OpenSSL,但未获取所有权引用,过早销毁easy han

AI Predicted 7.5 Difficulty: Hard EPSS 0.90% · P58

Possible ATT&CK Techniques 1 AI

T1204 · User Execution

Affected Version Matrix 14

VendorProduct Version RangeStatus
curl curl 8.14.0< 8.14.2 affected
8.15.0< 8.16.1 affected
8.17.0< 8.20.1 affected
8.21.0< 8.22.0 affected
f2ce6c46b9dcc46ced0ce43fa95176ea7599a854< 7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb affected
8.21.0 affected
8.20.0 affected
8.19.0 affected
… +6 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80229

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenSSL provider use-after-free
Source: CVE Program / CVE List V5
Vulnerability Description
When performing transfers via libcurl’s multi interface, pooled TLS connections can outlive their originating easy handles. In OpenSSL 3 provider configurations, libcurl attaches an allocated library context to the easy handle's state and passes it to OpenSSL without acquiring an ownership reference; destroying the easy handle prematurely frees this context while the active connection retains a dangling pointer, leading to a heap-use-after-free upon subsequent I/O or post-handshake operations.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
释放后使用
Source: CVE Program / CVE List V5
Vulnerability Title
curl 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 8.21.0版本、8.20.0版本、8.19.0版本、8.18.0版本、8.17.0版本、8.16.0版本、8.15.0版本、8.14.1版本和8.14.0版本存在资源管理错误漏洞,该漏洞源于通过libcurl的multi接口执行传输时,在OpenSSL 3 provider配置下,libcurl将已分配的库上下文附加到easy handle状态并传递给OpenSSL,但未获取所有权引用,过早销毁easy han
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
curl curl 8.14.0 ~ 8.14.2 -
curl curl f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 ~ 7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb -
curl curl 8.21.0 -

II. Public POCs for CVE-2026-80229

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80229

登录查看更多情报信息。

Vendor Advisories for CVE-2026-80229 (1)

Proof of Concept for CVE-2026-80229 (1)

Vendor Pages for CVE-2026-80229 (1)

Same Patch Batch · curl · 2026-09-06 · 9 CVEs total

CVE-2026-82208 wolfSSL CA-cache hit overrides callback
CVE-2026-82209 domain-scoped PSL domain cookie
CVE-2026-18924 HTTP/2 server push UAF
CVE-2026-19931 Negotiate ambient user conn reuse
CVE-2026-80231 native CA store conn reuse
CVE-2026-80230 OpenSSL pinning bypass
CVE-2026-80255 secure cookie attribute bypass with tab
CVE-2026-13608 OpenLDAP SASL authentication bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-80229

No comments yet


Leave a comment