Skip to main content

CVE detail

CVE-2026-8925

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.

CVSS 9.8 · CriticalBuzz score 39.5

Buzz score

Why this CVE is surfacing

Buzz score total 39.5

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 19.5 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
19.5
6 evidence mentions in the snapshot
Diversity score
20.0
5 sources across 4 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
4
within the 30d window
Peak daily
3
highest bucket

Evidence

Source links by recency

Newest mentions first
6 source links · newest first
  • CVE-2026-8925 SASL double-freeMicrosoft MSRC

    Information published.

    vendormsrc.microsoft.comJul 9, 2026, 8:49 AM
  • https://hackerone.com/reports/3735193hackerone.com

    No excerpt available.

    Exploithackerone.comJul 3, 2026, 7:16 AM
  • No excerpt available.

    Vendor Advisorycurl.seJul 3, 2026, 7:16 AM
  • No excerpt available.

    Vendor Advisorycurl.seJul 3, 2026, 7:16 AM
  • Curl fixed 18 vulnerabilities, including a 25-year-old bug, with issues spanning auth bypass, memory safety, and host validation in libcurl. Curl maintainers addressed eighteen vulnerabilities with a single update, and one of them goes back 25 years. That’s not a typo, it really sat there since the early 2000s. curl is a widely used open-source […]

    newssecurityaffairs.comJun 25, 2026, 7:20 PM
  • The latest version of the open source data transfer tool resolves 18 medium and low-severity vulnerabilities.

    newswww.securityweek.comJun 25, 2026, 9:25 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence