CVE-2026-9080: UAF after pause in socket callback
Published Jul 3, 2026
·Updated
Calling curleasypause() within the event-based CURLMOPTSOCKETFUNCTION callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.
Affected Software
2 affected componentsFixes available
debian/curl<=8.14.1-2+deb13u3, <=8.20.0-5
7.74.0-1.3+deb11u137.74.0-1.3+deb11u167.88.1-10+deb12u147.88.1-10+deb12u58.21.0-2
haxx curl>=8.13.0<8.21.0
Remediation
Patch Available
Event History
Jul 1, 2026
Data Sourced
via Debian·03:07 AM
DescriptionAffected Software
Jul 3, 2026
Data Sourced
via Ubuntu·03:08 AM
RemedyDescriptionSeverityAffected Software
CVE Published
via MITRE·06:17 AM
Data Sourced
via MITRE·06:17 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 11, 58531
Event
via FIRST·03:19 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-9080?
CVE-2026-9080 has a risk score of 21, indicating a high severity level due to potential exploitation.
2
How do I fix CVE-2026-9080?
To fix CVE-2026-9080, update to the latest version of libcurl that addresses this use-after-free vulnerability.
3
What is the nature of the vulnerability in CVE-2026-9080?
CVE-2026-9080 is a use-after-free vulnerability triggered by calling `curl_easy_pause()` in a specific callback.
4
Which software is affected by CVE-2026-9080?
CVE-2026-9080 affects the debian/curl software package.
5
When was CVE-2026-9080 published?
CVE-2026-9080 was published on July 3, 2026.