CVE-2026-82209
published 2026-09-06CVE-2026-82209: When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain`…
PriorityP350high8.2CVSS 3.1
AVNACLPRNUINSUCLIHAN
EPSS
0.37%
28.7th percentile
When libpsl support is enabled, libcurl fails to enforce the Public Suffix
List boundary check when processing a `Set-Cookie` header where the `Domain`
attribute explicitly matches an origin host that is itself a public suffix
(e.g., `Domain=co.uk` set by `co.uk`).
Instead of coercing it into a strict host-only cookie, libcurl saves the
cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is
inappropriately included in subsequent outbound requests or HTTP redirects to
arbitrary sibling subdomains under the same public suffix (e.g.,
`attacker.co.uk`).
Affected
104 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
| curl | curl | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
vendor_redhat8.2HIGH
vendor_ubuntu7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that
ghsa_unreviewed·2026-09-06
CVE-2026-82209 When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that
When libpsl support is enabled, libcurl fails to enforce the Public Suffix
List boundary check when processing a `Set-Cookie` header where the `Domain`
attribute explicitly matches an origin host that is itself a public suffix
(e.g., `Domain=co.uk` set by `co.uk`).
Instead of coercing it into a strict host-only cookie, libcurl saves the
cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is
inappropriately included in subsequent outbound requests or HTTP redirects to
arbitrary sibling subdomains under the same public suffix (e.g.,
`attacker.co.uk`).
VulDB
curl libcurl up to 8.21.0 Cookie Processing insertion of sensitive information into sent data (EUVD-2026-72153)
vuldb·2026-09-06
CVE-2026-82209 [LOW] curl libcurl up to 8.21.0 Cookie Processing insertion of sensitive information into sent data (EUVD-2026-72153)
A vulnerability was found in curl libcurl. It has been declared as problematic. This vulnerability affects unknown code of the component Cookie Processing. The manipulation results in insertion of sensitive information into sent data.
This vulnerability was named CVE-2026-82209. The attack may be performed from remote. There is no available exploit.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-09-24·CVSS 7.4
CVE-2026-80229 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Eunsoo Kim discovered that curl incorrectly handled SASL negotiation for
LDAP authentication in certain circumstances. A machine-in-the-middle
attacker could possibly use this issue to bypass peer validation. This
issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-13608)
Stephan Zeisberg discovered that curl incorrectly handled HTTP/2 Server
Push streams when sharing connections between handles. A remote attacker
could possibly use this issue to cause curl to crash, resulting in a denial
of service, or execute arbitrary code. (CVE-2026-18924)
Stanislav Fort discovered that curl incorrectly managed the lifetime of
pooled TLS connections when using the multi interface. An attacker could
pos
Red Hat
curl: libcurl: Information disclosure via improper Public Suffix List boundary check
vendor_redhat·2026-09-06·CVSS 8.2
CVE-2026-82209 [HIGH] CWE-501 curl: libcurl: Information disclosure via improper Public Suffix List boundary check
curl: libcurl: Information disclosure via improper Public Suffix List boundary check
When libpsl support is enabled, libcurl fails to enforce the Public Suffix
List boundary check when processing a `Set-Cookie` header where the `Domain`
attribute explicitly matches an origin host that is itself a public suffix
(e.g., `Domain=co.uk` set by `co.uk`).
Instead of coercing it into a strict host-only cookie, libcurl saves the
cookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is
inappropriately included in subsequent outbound requests or HTTP redirects to
arbitrary sibling subdomains under the same public suffix (e.g.,
`attacker.co.uk`).
A flaw was found in libcurl when libpsl support is enabled. A remote attacker could exploit this vulnerability by setting a `Set-Cookie` h
No detection rules found.
No public exploits indexed.
2026-09-06
Published