{"id":"CVE-2026-80229","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-80229","summary":"OpenSSL provider use-after-free","details":"When performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3 provider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while the\nactive connection retains a dangling pointer, leading to a heap-use-after-free\nupon subsequent I/O or post-handshake operations.","published":"2026-09-02T08:00:00Z","modified":"2026-09-07T14:06:38.707923Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-07T14:06:38.707923Z"}}