Description
When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
Problem types
Product status
8.18.0 (semver)
8.17.0 (semver)
8.16.0 (semver)
8.15.0 (semver)
8.14.1 (semver)
8.14.0 (semver)
8.13.0 (semver)
Credits
Daniel Wade
Stefan Eissing
References
www.openwall.com/lists/oss-security/2026/03/11/4
curl.se/docs/CVE-2026-3805.json (json)
curl.se/docs/CVE-2026-3805.html (www)
hackerone.com/reports/3591944 (issue)