The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
Critical CVSS 9.8
Summary
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://curl.se/docs/CVE-2026-8925.html Patch
- https://curl.se/docs/CVE-2026-8925.json Vendor Advisory
- https://hackerone.com/reports/3735193 Exploit
- https://hackerone.com/reports/3735193 Exploit
Timeline
- nvd_ingest NVD