Description


Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.

Related CPE's


Vulnerable

References




https://hackerone.com/reports/3749204

ExploitIssue TrackingThird Party Advisory

https://hackerone.com/reports/3749204

ExploitIssue TrackingThird Party Advisory

Weaknesses


2499f714-1537-4658-8207-48ae4bb9eae9

Secondary

CWE-416


CWE-416

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

7.3 · High

Information


Source identifier

2499f714-1537-4658-8207-48ae4bb9eae9

Vulnerability status

Modified

Published

2026-07-03T07:16:25.713Z

3 months ago

Last modified

2026-09-15T07:16:34.767Z

3 weeks ago