ECHO-6728-a303-47fd

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-6728-a303-47fd.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-6728-a303-47fd
Upstream
Withdrawn
2026-07-06T11:45:03.082Z
Published
2026-07-06T11:45:03.082Z
Modified
2026-07-29T18:24:00.311903147Z
Summary
Double-free in the GSASL auth context cleanup (SASL over IMAP/POP3/SMTP). The vulnerable second cleanup path was introduced in curl 8.15.0 by commit ab650379 (vauth: move auth structs to conn meta data with auto cleanup). Trixie ships 8.14.1, which predates it, so the double-free cannot occur. Debian marks this not-affected (vulnerable code not present); affected range is 8.15.0-8.20.0.
Details
References

Affected packages

Echo / curl

Package

Name
curl
Purl
pkg:deb/echo/curl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.14.1-2+deb13u3

Database specific

source
"https://advisory.echohq.com/osv/ECHO-6728-a303-47fd.json"