Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
Hello, The CVE-2026-10536 vulnerability impacts curl versions 7.88.0 --> 8.20.0. Davix embeds curl v7.69.0 for EPEL8, whereas for all other platforms it uses the system-provided curl, with no exact version pinned. This vulnerability does not impact Davix on EPEL8. On all other platforms, it is resolved by bringing a patched curl version. Closing as not a vulnerability to address in Davix. Cheers, Mihai