When doing a second SMB request to the same host again, curl would wrongly use a data pointer pointing into already freed memory.
https://github.com/Rat5ak/Rat5ak-Nadsec-2026-CVE-CERTIFIED-HOOD-CLASSICS
https://github.com/Rat5ak/CVE-2026-3805-curl-SMB-UAF
https://hackerone.com/reports/3591944
https://curl.se/docs/CVE-2026-3805.json