CVE-2026-3805 is a use-after-free vulnerability in curl and libcurl SMB connection reuse affecting versions 8.13.0 through 8.18.0. During a second SMB request to the same host, curl can retain a pointer into freed memory. The vulnerable code calls strlen() on that pointer, checks whether the resulting length is at most 1024 bytes, and copies the referenced data into an outgoing packet. If the freed memory is reused by the application between transfers, data from that memory region can potentially be exposed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small proof-of-concept and write-up for CVE-2026-3805, a use-after-free in curl/libcurl's SMB connection reuse logic. The repo contains 4 files: a README with root-cause analysis, impact, affected versions, and fix details; a large SECURITY_AUDIT_FINDINGS.md document with broader curl audit notes; a .gitignore; and one executable PoC script at poc/REPRODUCE_UAF.sh. The only actual exploit/reproduction code is the Bash script. The exploit capability is limited to triggering the vulnerability rather than delivering a post-exploitation payload. It demonstrates that two SMB requests to the same server can cause req->path to reference freed heap memory after connection reuse. When curl constructs the second SMB OPEN request, it reads from the dangling pointer via strlen() and copies the data into the outbound SMB packet. As a result, the bug can produce denial of service via crash and potentially disclose heap contents to an attacker-controlled SMB server. The PoC script automates building a vulnerable curl from source with SMB enabled and AddressSanitizer instrumentation, then provides multiple reproduction paths: using any reachable SMB server, setting up local Samba shares, or using a minimal TCP listener on port 445. Notably, the script states that a fully functional SMB server is not required because the vulnerable read occurs during smb_send_open before a valid SMB response is needed. This makes the repository a practical reproduction aid for vulnerability validation. There is no exploit framework involved, no shellcode, and no persistence or lateral movement logic. The repository's purpose is vulnerability documentation, root-cause explanation, and reliable crash/info-leak reproduction for affected curl/libcurl SMB builds.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.