libcurl package version has security vulnerabilities
We are recieving below vulnerabilities from HVR libcurl package:
libcurl 7.88.0 < 8.21.0 HTTP/2 Stream-Dependency Tree Use-After-Free
The version of libcurl installed on the remote host is 7.88.0 prior to 8.21.0. It is, therefore, affected by a use-after-free vulnerability:
- A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree and subsequently invokes curl_easy_reset(). (CVE-2026-10536)
Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.
Please sign in to leave a comment.
Comments
0 comments