CVE-2023-46218
published 2023-12-07CVE-2023-46218: This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible…
PriorityP337medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.69%
74.0th percentile
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.4.0 – 8.4.0 | — |
| debian | curl | < curl 7.88.1-10+deb12u5 (bookworm) | curl 7.88.1-10+deb12u5 (bookworm) |
| fedoraproject | fedora | — | — |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 8.5.0-r0 | 8.5.0-r0 |
| haxx | curl | >= 0 < 7.74.0-1.3+deb11u11 | 7.74.0-1.3+deb11u11 |
| haxx | curl | >= 0 < 7.88.1-10+deb12u5 | 7.88.1-10+deb12u5 |
| haxx | curl | >= 0 < 8.5.0-1 | 8.5.0-1 |
| haxx | curl | >= 0 < 8.5.0-1 | 8.5.0-1 |
| haxx | curl | >= 0 < 7.68.0-1ubuntu2.21 | 7.68.0-1ubuntu2.21 |
| haxx | curl | >= 0 < 7.81.0-1ubuntu1.15 | 7.81.0-1ubuntu1.15 |
| haxx | curl | 7.46.0 – 8.4.0 | — |
| msrc | azl3_cmake_3.28.2-6_on_azure_linux_3.0 | — | — |
| msrc | azl3_cmake_3.29.6-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_mysql_8.0.36-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_mysql_8.0.40-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-14_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.86.0-1_on_azure_linux_3.0 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2018-6594 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite (curl) — CVE-2023-46218
vendor_oracle·2025-01-15·CVSS 6.5
CVE-2023-46218 [MEDIUM] Oracle Oracle Communications Risk Matrix: Automated Test Suite (curl) — CVE-2023-46218
Oracle Oracle Communications Risk Matrix: Automated Test Suite (curl) vulnerability
CVE: CVE-2023-46218
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-11-14
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateNovember 14, 2024
Alert CodeICSA-24-319-04
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Out-of-bounds Write, Uncontro
Oracle
Oracle Oracle Communications Applications Risk Matrix: Installation (curl) — CVE-2023-46218
vendor_oracle·2024-07-15·CVSS 6.5
CVE-2023-46218 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Installation (curl) — CVE-2023-46218
Oracle Oracle Communications Applications Risk Matrix: Installation (curl) vulnerability
CVE: CVE-2023-46218
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
CISA ICS
Siemens SIMATIC RTLS Locating Manager
cisa_ics·2024-05-16
Siemens SIMATIC RTLS Locating Manager
ICS Advisory
##
Siemens SIMATIC RTLS Locating Manager
Release DateMay 16, 2024
Alert CodeICSA-24-137-07
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 10.0
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC RTLS Locating Manager
- Vulnerabilities: Improper Input Validation, Improper Check for Unusual or Exceptional Conditions, Uncontrolled Resource Consumption, Excessive Iteration, Allocation of Resources Wi
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (curl) — CVE-2023-46218
vendor_oracle·2024-04-15·CVSS 6.5
CVE-2023-46218 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (curl) — CVE-2023-46218
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (curl) vulnerability
CVE: CVE-2023-46218
CVSS: 6.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Ubuntu
curl vulnerability
vendor_ubuntu·2024-02-19
CVE-2023-46218 curl vulnerability
Title: curl vulnerability
Summary: curl could be made to set cookies that would bypass PSL checks.
Harry Sintonen discovered that curl incorrectly handled mixed case cookie
domains. A remote attacker could possibly use this issue to set cookies
that get sent to different and unrelated sites and domains.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that the
vendor_msrc·2023-12-12·CVSS 6.5
CVE-2023-46218 [MEDIUM] This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that the
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk` even though `co.uk` is listed as a PSL domain.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the co
Red Hat
curl: information disclosure by exploiting a mixed case flaw
vendor_redhat·2023-12-06·CVSS 6.5
CVE-2023-46218 [MEDIUM] CWE-201 curl: information disclosure by exploiting a mixed case flaw
curl: information disclosure by exploiting a mixed case flaw
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
A flaw was found in curl that verifies a given cookie domain against the Public Suffix List. This issue could allow a malicious HTTP server to set "super cookies" in curl that a
Ubuntu
curl vulnerabilities
vendor_ubuntu·2023-12-06·CVSS 6.5
CVE-2023-46219 [MEDIUM] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen discovered that curl incorrectly handled mixed case cookie
domains. A remote attacker could possibly use this issue to set cookies
that get sent to different and unrelated sites and domains.
(CVE-2023-46218)
Maksymilian Arciemowicz discovered that curl incorrectly handled long file
names when saving HSTS data. This could result in curl losing HSTS data,
and subsequent requests to a site would be done without it, contrary to
expectations. This issue only affected Ubuntu 23.04 and Ubuntu 23.10.
(CVE-2023-46219)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-46218: curl - This flaw allows a malicious HTTP server to set "super cookies" in curl that are...
vendor_debian·2023·CVSS 6.5
CVE-2023-46218 [MEDIUM] CVE-2023-46218: curl - This flaw allows a malicious HTTP server to set "super cookies" in curl that are...
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
Scope: local
bookworm: resolved (fixed in 7.88.1-10+deb12u5)
bullseye: resolved (fixed in 7.74.0-1.3+deb11u11)
forky: resolved (fixed in 8.5.0-1)
sid: resolved (fixed in 8.5.0-1)
trixie: resolved (fixed in 8.5.0-1)
OSV
CVE-2023-46218: This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
po
osv·2023-12-07·CVSS 6.5
CVE-2023-46218 [MEDIUM] CVE-2023-46218: This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
po
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
OSV
CVE-2023-46218: This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or po
osv·2023-12-07·CVSS 6.5
CVE-2023-46218 [MEDIUM] CVE-2023-46218: This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or po
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
GHSA
GHSA-59mm-6rr4-j9p2: This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
po
ghsa_unreviewed·2023-12-07
CVE-2023-46218 [MEDIUM] CWE-178 GHSA-59mm-6rr4-j9p2: This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
po
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
OSV
curl vulnerabilities
osv·2023-12-06·CVSS 6.5
CVE-2023-46218 [MEDIUM] curl vulnerabilities
curl vulnerabilities
Harry Sintonen discovered that curl incorrectly handled mixed case cookie
domains. A remote attacker could possibly use this issue to set cookies
that get sent to different and unrelated sites and domains.
(CVE-2023-46218)
Maksymilian Arciemowicz discovered that curl incorrectly handled long file
names when saving HSTS data. This could result in curl losing HSTS data,
and subsequent requests to a site would be done without it, contrary to
expectations. This issue only affected Ubuntu 23.04 and Ubuntu 23.10.
(CVE-2023-46219)
No detection rules found.
No public exploits indexed.
HackerOne
curl cookie mixed case PSL bypass
hackerone·2023-12-22·CVSS 6.5
[MEDIUM] curl cookie mixed case PSL bypass
curl cookie mixed case PSL bypass
A vulnerability in curl allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with domain=co.UK when the URL used a lowercase hostname curl.co.uk, even though co.uk is listed as a PSL domain.
## Impact
Issue supercookies bypassing the Public Suffix List check.
CVE-2023-46218 - cookie mixed case PSL bypass
VULNERABILITY
This flaw allows a malicious HTTP server to set "super cookies"
HackerOne
CVE-2023-46218: cookie mixed case PSL bypass
hackerone·2023-12-06·CVSS 6.5
CVE-2023-46218 [MEDIUM] CVE-2023-46218: cookie mixed case PSL bypass
CVE-2023-46218: cookie mixed case PSL bypass
## Summary:
libcurl fails to normalize the `hostname` and `cookie_domain` parameters passed to `psl_is_cookie_domain_acceptable` function. As a result a malicious site can set a super cookie if the victim requests the url with hostname with any upper case characters in the domain part of the hostname.
libpsl `psl_is_cookie_domain_acceptable` documentation https://rockdaboot.github.io/libpsl/libpsl-Public-Suffix-List-functions.html#psl-is-cookie-domain-acceptable says the following:
```
Use helper function psl_str_to_utf8lower() for normalization of hostname and cookie_domain .
```
This is not done correctly and hence domains with uppercase characters will bypass the PSL check. Note that curl itself will later ignore the cookie domain capitaliz
https://curl.se/docs/CVE-2023-46218.htmlhttps://hackerone.com/reports/2212193https://lists.debian.org/debian-lts-announce/2023/12/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3ZX3VW67N4ACRAPMV2QS2LVYGD7H2MVE/https://lists.fedoraproject.org/archives/list/[email protected]/message/UOGXU25FMMT2X6UUITQ7EZZYMJ42YWWD/https://security.netapp.com/advisory/ntap-20240125-0007/https://www.debian.org/security/2023/dsa-5587https://curl.se/docs/CVE-2023-46218.htmlhttps://hackerone.com/reports/2212193https://lists.debian.org/debian-lts-announce/2023/12/msg00015.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3ZX3VW67N4ACRAPMV2QS2LVYGD7H2MVE/https://lists.fedoraproject.org/archives/list/[email protected]/message/UOGXU25FMMT2X6UUITQ7EZZYMJ42YWWD/https://security.netapp.com/advisory/ntap-20240125-0007/https://www.debian.org/security/2023/dsa-5587https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-093430.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-202008.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-331112.html
2023-12-07
Published