AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2021-22901.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.1CVSS 3.1 · nvd@nist.gov
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSModifiedModified Oct 08, 2026

Disclosure summary

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at run-time sets up support for TLS 1.3 session tickets on a connection using OpenSSL, it stores pointers to the transfer in-memory object for later retrieval when a session ticket arrives. If the connection is used by multiple transfers (like with a reused HTTP/1.1 connection or multiplexed HTTP/2 connection) that first transfer object might be freed before the new session is established on that connection and then the function will access a memory buffer that might be freed. When using that memory, libcurl might even call a function pointer in the object, making it possible for a remote code execution if the server could somehow manage to get crafted memory content into the correct place in memory.

Source-reported weakness categories

CWE-416

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2021-22901

Open original source · Updated Oct 08, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

VendorProduct / associationVersion / bounds
haxxcurl* {"versionStartIncluding":"7.75.0","versionEndIncluding":"7.76.1"}
oraclecommunications_cloud_native_core_binding_support_function1.11.0
oraclecommunications_cloud_native_core_network_function_cloud_native_environment1.10.0
oraclecommunications_cloud_native_core_network_repository_function1.15.0
oraclecommunications_cloud_native_core_network_repository_function1.15.1
oraclecommunications_cloud_native_core_network_slice_selection_function1.8.0
oraclecommunications_cloud_native_core_service_communication_proxy1.15.0
oracleessbase* {"versionStartIncluding":"21.0","versionEndExcluding":"21.3"}
oraclemysql_server* {"versionStartIncluding":"8.0.0","versionEndIncluding":"8.0.25"}
netappactive_iq_unified_manager-
netappactive_iq_unified_manager-
netappcloud_backup-
netapponcommand_insight-
netapponcommand_workflow_automation-
netappsnapcenter-
netappsolidfire,_enterprise_sds_&_hci_storage_node-
netappsolidfire_&_hci_management_node-
netappsolidfire_baseboard_management_controller_firmware-
netapphci_compute_node_firmware-
netapph300e_firmware-
netapph300s_firmware-
netapph410s_firmware-
netapph500e_firmware-
netapph500s_firmware-
netapph700e_firmware-
netapph700s_firmware-
siemenssinec_infrastructure_network_services* {"versionEndExcluding":"1.0.1.1"}
splunkuniversal_forwarder* {"versionStartIncluding":"9.0.0","versionEndExcluding":"9.0.6"}
splunkuniversal_forwarder9.1.0

Original records & references

PUBLISHED 2021-06-11T12:15:11-04:00
MODIFIED 2026-10-08T17:17:33-04:00
INGESTED 2026-10-10T20:50:20-04:00