<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 05:16:58 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-18924 — HTTP/2 server push UAF</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-18924</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; curl&lt;/p&gt;
&lt;p&gt;A flaw in libcurl&amp;#39;s handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; curl&lt;/p&gt;
&lt;p&gt;A flaw in libcurl&amp;#39;s handling of HTTP/2 Server Push streams, when the parent
handle is set to share connections with other handles, can lead to
use-after-free in the cleanup process.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-18924</guid>
    </item>
    <item>
      <title>USN-8820-1 — curl vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-8820-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:Pro:20.04:LTS: curl, Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl, Ubuntu:26.04:LTS: curl&lt;/p&gt;
&lt;p&gt;Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for
LDAP authentication in certain circumstances. A machine-in-the-middle
attacker could possibly use this issue to bypass peer validation. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-13608)&lt;/p&gt;
&lt;p&gt;Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server
Push streams when sharing connections between handles. A remote attacker
could possibly use this issue to cause curl to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-18924)&lt;/p&gt;
&lt;p&gt;Stanislav Fort discovered that curl incorrectly managed the lifetime of
pooled TLS connections when using the multi interface. An attacker could
possibly use this issue to cause curl to crash, resulting in a denial of
service, or execute arbitrary code. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-80229)&lt;/p&gt;
&lt;p&gt;Stanislav Fort discovered that curl did not properly enforce public key
pinning when certificate verification was disabled in certain
circumstances. A remote attacker could possibly use this issue to bypass
pinning checks and cause curl to accept connections that should have been
rejected. (CVE-2026-80230)&lt;/p&gt;
&lt;p&gt;Stanislav Fort discovered that curl incorrectly handled the Secure
attribute of cookies in certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-80255)&lt;/p&gt;
&lt;p&gt;Stanislav Fort discovered that curl did not proper…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: curl, Ubuntu:Pro:18.04:LTS: curl, Ubuntu:Pro:20.04:LTS: curl, Ubuntu:22.04:LTS: curl, Ubuntu:24.04:LTS: curl, Ubuntu:26.04:LTS: curl&lt;/p&gt;
&lt;p&gt;Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for
LDAP authentication in certain circumstances. A machine-in-the-middle
attacker could possibly use this issue to bypass peer validation. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-13608)&lt;/p&gt;
&lt;p&gt;Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server
Push streams when sharing connections between handles. A remote attacker
could possibly use this issue to cause curl to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-18924)&lt;/p&gt;
&lt;p&gt;Stanislav Fort discovered that curl incorrectly managed the lifetime of
pooled TLS connections when using the multi interface. An attacker could
possibly use this issue to cause curl to crash, resulting in a denial of
service, or execute arbitrary code. This issue only affected Ubuntu 26.04
LTS. (CVE-2026-80229)&lt;/p&gt;
&lt;p&gt;Stanislav Fort discovered that curl did not properly enforce public key
pinning when certificate verification was disabled in certain
circumstances. A remote attacker could possibly use this issue to bypass
pinning checks and cause curl to accept connections that should have been
rejected. (CVE-2026-80230)&lt;/p&gt;
&lt;p&gt;Stanislav Fort discovered that curl incorrectly handled the Secure
attribute of cookies in certain circumstances. A remote attacker could
possibly use this issue to obtain sensitive information. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-80255)&lt;/p&gt;
&lt;p&gt;Stanislav Fort discovered that curl did not proper…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-8820-1</guid>
    </item>
  </channel>
</rss>
