CVE-2016-8619: Haxx Curl

Critical severity, CVSS 9.8. EPSS: 5% chance of exploitation in the next 30 days.

The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.

Affected products

  • Haxx Curl: before 7.51.0 (fixed in 7.51.0)

Published 2018-08-01. Last modified 2026-06-17.