CVE-2026-8924
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.66%
- CWE
- CWE-201
- Published
- 2026-07-03
- Last modified
- 2026-09-15
Affected products
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
Weakness type
Related vulnerabilities
- CVE-2026-24477 — AnythingLLM has key leak in `systemSettings.js`
- CVE-2026-47717 — FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts and Device Configurations
- CVE-2026-27934 — Discourse leaks private topic title and post excerpt via user action API endpoint
- CVE-2025-11500 — Credentials exposure in tinycontrol devices
- CVE-2020-37093 — Netis E1+ 1.2.32533 - Unauthenticated WiFi Password Leak
- CVE-2026-27516 — Binardat 10G08-0800GSM Network Switch Plaintext Password Exposure
- CVE-2025-66566 — yawkat LZ4 Java has a possible information leak in Java safe decompressor
- CVE-2026-39912 — v2board / Xboard Authentication Token Exposure via loginWithMailLink