CVE-2026-10536False Positive(haxx / curl)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch haxx curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • False Positive: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-19)
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-07-08: 1Mentions · 2026-07-09: 1Mentions · 2026-08-01: 1Mentions · 2026-08-19: 2Patch / Workaround · 2026-07-08: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 1Technical Details · 2026-08-19: 107-0807-0908-0108-19
Signal classification3 categories
False Positive
360.0%
Patch
120.0%
Disclosure
120.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-081
Patch1
2026-07-091
False Positive1
2026-08-011
Disclosure1
2026-08-192
False Positive2
Full discourse5 posts
  • JFrog Security@JFrogSecurity
    False Positive

    🚨 Overhyped vulnerability of the week: Severity inflation in Curl CVE-2026-10536 (Critical 9.8 CVSS, but no security impact). Can a vulnerability truly be critical if it just causes a client crash, regardless of external input? 🧵

    Post summary

    The tweet argues that CVE-2026-10536 is overhyped, citing its severe CVSS rating yet claiming no real security impact.

    1401282.0K
    5.6K followersView on X
  • Lyrie.ai@lyrie_ai
    False Positive

    CVE-2026-10536: 🚨 Overhyped vulnerability of the week: Severity inflation in Curl CVE-2026-10536 (Critical 9.8 CVSS, but no security impact). Can a vulnerability truly be critical if it just causes a client crash, regardless of external input? 🧵 (9.8)

    Post summary

    The text debunks the perceived severity of CVE‑2026‑10536, noting it only causes a client crash without security impact, but does not provide PoC, exploit, or patch details.

    1000038
    324 followersView on X
  • Lyrie.ai@lyrie_ai
    False Positive

    Full Tweet 🚨 Overhyped vulnerability of the week: Severity inflation in Curl CVE-2026-10536 (Critical 9.8 CVSS, but no security impact). 0day Intel: 🚨 Overhyped vulnerability of the week: Severity inflation in Curl CVE-2026-1053

    Post summary

    The tweet asserts that CVE‑2026‑10536 (and CVE‑2026‑1053) are overhyped, with a critical score but no real security impact, effectively labeling them as false positives.

    1000028
    324 followersView on X
  • guriguri@guriguri_dW
    Disclosure

    #IBMAIX ■ Security Bulletin: Multiple vulnerabilities impact AIX due to CURL libcurl (CVE-2026-10536, CVE-2026-11856, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8927, CVE-2026-8932, CVE-2026-9547). https://www.ibm.com/support/pages/node/7281743 沢山あります! 😱

    Post summary

    IBM issued a security bulletin listing multiple CVE vulnerabilities affecting AIX’s libcurl implementation, urging users to consult the linked advisory for details.

    0000051
    123 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    curl hit with a critical UAF 🔗 CVE-2026-10536: manipulating HTTP/2 stream-dependency trees via CURLOPT_STREAM_DEPENDS can corrupt freed memory — CVSS 9.8, no auth needed. Patch libcurl now. #curl #cybersecurity https://secalerts.co/vulnerability/CVE-2026-10536?utm_campaign=x https://t.co/NgH9OjXakd

    Post summary

    The tweet announces CVE‑2026‑10536, a critical use‑after‑free in libcurl, provides technical details and a CVSS score, and states that a patch is now available.

    00000108
    852 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more