CVE-2022-32205
published 2022-07-07CVE-2022-32205: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large…
PriorityP431medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
26.91%
97.8th percentile
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set cookies that also would match for `bar.example.com`, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the same second level domain using this method.
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | macos | < 13.0 | 13.0 |
| apple | macos_ventura | — | — |
| debian | curl | < curl 7.84.0-1 (bookworm) | curl 7.84.0-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 7.74.0-1.3+deb11u2 | 7.74.0-1.3+deb11u2 |
| haxx | curl | >= 0 < 7.84.0-1 | 7.84.0-1 |
| haxx | curl | >= 0 < 7.84.0-1 | 7.84.0-1 |
| haxx | curl | >= 0 < 7.84.0-1 | 7.84.0-1 |
| haxx | curl | >= 0 < 7.58.0-2ubuntu3.19 | 7.58.0-2ubuntu3.19 |
| haxx | curl | >= 0 < 7.68.0-1ubuntu2.12 | 7.68.0-1ubuntu2.12 |
| haxx | curl | >= 0 < 7.81.0-1ubuntu1.3 | 7.81.0-1ubuntu1.3 |
| haxx | curl | >= 0 < 7.81.0-1ubuntu1.21 | 7.81.0-1ubuntu1.21 |
| haxx | curl | >= 7.71.0 < 7.84.0 | 7.84.0 |
| https | github.com_curl_curl | — | — |
| msrc | cbl2_curl_7.84.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_curl_7.84.0-1_on_cbl_mariner_1.0 | — | — |
| siemens | scalance_sc622-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc626-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc632-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc636-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc642-2c_firmware | < 3.0 | 3.0 |
| siemens | scalance_sc646-2c_firmware | < 3.0 | 3.0 |
| splunk | universal_forwarder | — | — |
| splunk | universal_forwarder | >= 8.2.0 < 8.2.12 | 8.2.12 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_msrc4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
curl regression
osv·2025-09-29·CVSS 4.3
CVE-2022-32205 [MEDIUM] curl regression
curl regression
USN-5495-1 fixed vulnerabilities in curl. The fix for CVE-2022-32205
miscalculated the maximum cookie size, causing a regression. This update
fixes the problem.
Original advisory details:
Harry Sintonen discovered that curl incorrectly handled certain cookies.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 21.10, and Ubuntu 22.04 LTS. (CVE-2022-32205)
Harry Sintonen discovered that curl incorrectly handled certain HTTP compressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-32206)
Harry Sintonen incorrectly handled certain file permissions.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 21.10, and Ubuntu 22.04 LTS.
GHSA
GHSA-9hhr-r3j8-h675: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7
ghsa_unreviewed·2022-07-08
CVE-2022-32205 [MEDIUM] CWE-770 GHSA-9hhr-r3j8-h675: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set cookies that also would match for `bar.example.com`, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the same second level domain using this met
OSV
CVE-2022-32205: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7
osv·2022-07-07·CVSS 4.3
CVE-2022-32205 [MEDIUM] CVE-2022-32205: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set cookies that also would match for `bar.example.com`, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the same second level domain using this met
OSV
curl vulnerabilities
osv·2022-06-27·CVSS 4.3
CVE-2022-32205 [MEDIUM] curl vulnerabilities
curl vulnerabilities
Harry Sintonen discovered that curl incorrectly handled certain cookies.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 21.10, and Ubuntu 22.04 LTS. (CVE-2022-32205)
Harry Sintonen discovered that curl incorrectly handled certain HTTP compressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-32206)
Harry Sintonen incorrectly handled certain file permissions.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 21.10, and Ubuntu 22.04 LTS. (CVE-2022-32207)
Harry Sintonen discovered that curl incorrectly handled certain FTP-KRB messages.
An attacker could possibly use this to perform a machine-in-the-middle attack.
(CVE-
Ubuntu
curl regression
vendor_ubuntu·2025-09-29·CVSS 4.3
CVE-2022-32205 [MEDIUM] curl regression
Title: curl regression
Summary: USN-5495-1 introduced a regression in curl
USN-5495-1 fixed vulnerabilities in curl. The fix for CVE-2022-32205
miscalculated the maximum cookie size, causing a regression. This update
fixes the problem.
Original advisory details:
Harry Sintonen discovered that curl incorrectly handled certain cookies.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 21.10, and Ubuntu 22.04 LTS. (CVE-2022-32205)
Harry Sintonen discovered that curl incorrectly handled certain HTTP compressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-32206)
Harry Sintonen incorrectly handled certain file permissions.
An attacker could possibly use this issue to expose sensitive information.
CISA ICS
Siemens SCALANCE XCM332
cisa_ics·2023-04-13·CVSS 7.5
[HIGH] Siemens SCALANCE XCM332
ICS Advisory
##
Siemens SCALANCE XCM332
Release DateApril 13, 2023
Alert CodeICSA-23-103-09
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM332
- Vulnerabilities: Allocation of Resources Without Limits or Throttling, Use After Free, Concurrent Execution Using Shared Resource with Improper Synchronization ('Race Condition'), Incorrect Default Permissions, Out-of-
CISA ICS
Siemens SCALANCE SC-600 Family
cisa_ics·2022-12-15
Siemens SCALANCE SC-600 Family
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE SC-600 Family
Last RevisedDecember 15, 2022
Alert CodeICSA-22-349-18
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE SC-600 Family
- Vulnerability: Out-of-bounds Write, Use After Free, Allocation of Resources Without Limits or Throttling
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow a denial-of-service condition, corrupt memory, or potentially execute custom code.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions
Apple
CVE-2022-32205: macOS Ventura 13
vendor_apple·2022-10-24·CVSS 4.3
CVE-2022-32205 [MEDIUM] CVE-2022-32205: macOS Ventura 13
Apple Security Update: About the security content of macOS Ventura 13
Product: macOS Ventura
Version: 13
CVE: CVE-2022-32205
Component: CVE-2022-32205
Microsoft
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HT
vendor_msrc·2022-07-12·CVSS 4.3
CVE-2022-32205 [MEDIUM] CWE-770 A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HT
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
hackerone: hackerone
Customer Action Required: Yes
Remed
Red Hat
curl: Set-Cookie denial of service
vendor_redhat·2022-06-27·CVSS 4.3
CVE-2022-32205 [MEDIUM] CWE-770 curl: Set-Cookie denial of service
curl: Set-Cookie denial of service
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set cookies that also would match for `bar.example.com`, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the sam
Ubuntu
curl vulnerabilities
vendor_ubuntu·2022-06-27·CVSS 4.3
CVE-2022-32207 [MEDIUM] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen discovered that curl incorrectly handled certain cookies.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 21.10, and Ubuntu 22.04 LTS. (CVE-2022-32205)
Harry Sintonen discovered that curl incorrectly handled certain HTTP compressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2022-32206)
Harry Sintonen incorrectly handled certain file permissions.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 21.10, and Ubuntu 22.04 LTS. (CVE-2022-32207)
Harry Sintonen discovered that curl incorrectly handled certain FTP-KRB messages.
An attacker could possi
Debian
CVE-2022-32205: curl - A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTT...
vendor_debian·2022·CVSS 4.3
CVE-2022-32205 [MEDIUM] CVE-2022-32205: curl - A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTT...
A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set cookies that also would match for `bar.example.com`, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the same second level domain using this met
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2022-32205: Set-Cookie denial of service
hackerone·2022-06-27·CVSS 4.3
CVE-2022-32205 [MEDIUM] CVE-2022-32205: Set-Cookie denial of service
CVE-2022-32205: Set-Cookie denial of service
A malicious server can serve excessive amounts of Set-Cookie: headers in a HTTP response to curl and curl stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.
This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on foo.example.com can set cookies that also would match for bar.example.com, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the same s
HackerOne
CVE-2022-32205: Set-Cookie denial of service
hackerone·2022-06-27·CVSS 4.3
CVE-2022-32205 [MEDIUM] CVE-2022-32205: Set-Cookie denial of service
CVE-2022-32205: Set-Cookie denial of service
## Summary:
Curl fails to limit the number of cookies that can be set by a single host/domain. It can easily lead to a situation where constructing the request towards a host will end up consuming more than `DYN_HTTP_REQUEST` memory, leading to instant `CURLE_OUT_OF_MEMORY`.
Any host in a given domain can target any other hosts in the same domain by using domain cookies. The attack works from both `HTTP` and `HTTPS` and from unprivileged ports.
## Steps To Reproduce:
1. Run the following python web server:
```
from http.server import BaseHTTPRequestHandler, HTTPServer
class MyServer(BaseHTTPRequestHandler):
def do_GET(self):
self.send_response(200)
for i in range(0,256):
self.send_header("Set-Cookie", "f{}={}; Domain=hax.invalid".format(i, "
http://seclists.org/fulldisclosure/2022/Oct/28http://seclists.org/fulldisclosure/2022/Oct/41https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdfhttps://hackerone.com/reports/1569946https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/https://security.gentoo.org/glsa/202212-01https://security.netapp.com/advisory/ntap-20220915-0003/https://support.apple.com/kb/HT213488https://www.debian.org/security/2022/dsa-5197http://seclists.org/fulldisclosure/2022/Oct/28http://seclists.org/fulldisclosure/2022/Oct/41https://cert-portal.siemens.com/productcert/pdf/ssa-333517.pdfhttps://hackerone.com/reports/1569946https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BEV6BR4MTI3CEWK2YU2HQZUW5FAS3FEY/https://security.gentoo.org/glsa/202212-01https://security.netapp.com/advisory/ntap-20220915-0003/https://support.apple.com/kb/HT213488https://www.debian.org/security/2022/dsa-5197
2022-07-07
Published