{"id":"CVE-2026-18924","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-18924","summary":"HTTP/2 server push UAF","details":"A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.","published":"2026-09-02T08:00:00Z","modified":"2026-09-07T14:06:33.197347Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-07T14:06:33.197347Z"}}