{"id":"CURL-CVE-2026-80229","summary":"OpenSSL provider use-after-free","details":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations.","aliases":["CVE-2026-80229"],"modified":"2026-09-02T14:00:20.030408Z","published":"2026-09-02T08:00:00Z","database_specific":{"affects":"both","issue":"https://hackerone.com/reports/3969255","last_affected":"8.21.0","package":"curl","severity":"Low","www":"https://curl.se/docs/CVE-2026-80229.html","CWE":{"desc":"Use After Free","id":"CWE-416"},"URL":"https://curl.se/docs/CVE-2026-80229.json"},"affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"8.14.0"},{"fixed":"8.22.0"}]},{"type":"GIT","repo":"https://github.com/curl/curl.git","events":[{"introduced":"f2ce6c46b9dcc46ced0ce43fa95176ea7599a854"},{"fixed":"7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb"}]}],"versions":["8.21.0","8.20.0","8.19.0","8.18.0","8.17.0","8.16.0","8.15.0","8.14.1","8.14.0","rc-8_22_0-2","rc-8_22_0-1","curl-8_21_0","rc-8_21_0-3","rc-8_21_0-2","rc-8_21_0-1","curl-8_20_0","rc-8_20_0-3","rc-8_20_0-2","rc-8_20_0-1","curl-8_19_0","rc-8_19_0-3","rc-8_19_0-2","rc-8_19_0-1","curl-8_18_0","rc-8_18_0-3","rc-8_18_0-2","rc-8_18_0-1","curl-8_17_0","curl-8_16_0","curl-8_15_0","curl-8_14_1","curl-8_14_0"],"database_specific":{"source":"https://curl.se/docs/CURL-CVE-2026-80229.json","vanir_signatures_modified":"2026-09-02T14:00:20Z","vanir_signatures":[{"target":{"file":"lib/vtls/openssl.c"},"deprecated":false,"digest":{"line_hashes":["286481243370392075526062118659509114348","196216237767420629426097604457509099271","68125101134514249852390309734181512406","31227070220736528463295638619520929314"],"threshold":0.9},"id":"CURL-CVE-2026-80229-49021c9f","signature_type":"Line","signature_version":"v1","source":"https://github.com/curl/curl.git/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/curl/curl.git/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb","target":{"file":"lib/vtls/openssl.c","function":"Curl_ossl_ctx_init"},"deprecated":false,"digest":{"function_hash":"93812128733312520413839406253910216274","length":4945},"id":"CURL-CVE-2026-80229-74875d56"}]}}],"schema_version":"1.9.0","credits":[{"name":"Stanislav Fort (Aisle Research)","type":"FINDER"},{"name":"Daniel Stenberg","type":"REMEDIATION_DEVELOPER"}]}