CVE-2026-8924
published 2026-07-03CVE-2026-8924: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an…
PriorityP356critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.65%
47.3th percentile
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
Affected
101 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 7.46.0 – 7.46.0 | — |
| curl | curl | 7.47.0 – 7.47.0 | — |
| curl | curl | 7.47.1 – 7.47.1 | — |
| curl | curl | 7.48.0 – 7.48.0 | — |
| curl | curl | 7.49.0 – 7.49.0 | — |
| curl | curl | 7.49.1 – 7.49.1 | — |
| curl | curl | 7.50.0 – 7.50.0 | — |
| curl | curl | 7.50.1 – 7.50.1 | — |
| curl | curl | 7.50.2 – 7.50.2 | — |
| curl | curl | 7.50.3 – 7.50.3 | — |
| curl | curl | 7.51.0 – 7.51.0 | — |
| curl | curl | 7.52.0 – 7.52.0 | — |
| curl | curl | 7.52.1 – 7.52.1 | — |
| curl | curl | 7.53.0 – 7.53.0 | — |
| curl | curl | 7.53.1 – 7.53.1 | — |
| curl | curl | 7.54.0 – 7.54.0 | — |
| curl | curl | 7.54.1 – 7.54.1 | — |
| curl | curl | 7.55.0 – 7.55.0 | — |
| curl | curl | 7.55.1 – 7.55.1 | — |
| curl | curl | 7.56.0 – 7.56.0 | — |
| curl | curl | 7.56.1 – 7.56.1 | — |
| curl | curl | 7.57.0 – 7.57.0 | — |
| curl | curl | 7.58.0 – 7.58.0 | — |
| curl | curl | 7.59.0 – 7.59.0 | — |
| curl | curl | 7.60.0 – 7.60.0 | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
curl: curl: Cookie injection via malicious HTTP server using super cookies
vendor_redhat·2026-07-03·CVSS 9.1
CVE-2026-8924 [CRITICAL] CWE-565 curl: curl: Cookie injection via malicious HTTP server using super cookies
curl: curl: Cookie injection via malicious HTTP server using super cookies
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.
Statement: Moderate: Red Hat rates this flaw Moderate (CVSS 6.5) compared to CISA's Critical (9.1). The scoring difference is du
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
GHSA
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check.
ghsa_unreviewed·2026-07-03
CVE-2026-8924 A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check.
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
bugzilla·2026-07-07·CVSS 9.1
CVE-2026-8924 [CRITICAL] CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
Bugzilla
CVE-2026-8924 rpi-imager: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
bugzilla·2026-07-07·CVSS 9.1
CVE-2026-8924 [CRITICAL] CVE-2026-8924 rpi-imager: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
CVE-2026-8924 rpi-imager: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
Bugzilla
CVE-2026-8924 mingw-curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
bugzilla·2026-07-07·CVSS 9.1
CVE-2026-8924 [CRITICAL] CVE-2026-8924 mingw-curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
CVE-2026-8924 mingw-curl: curl: Cookie injection via malicious HTTP server using super cookies [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
Bugzilla
CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
bugzilla·2026-07-03·CVSS 9.1
CVE-2026-8924 [CRITICAL] CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
CVE-2026-8924 curl: curl: Cookie injection via malicious HTTP server using super cookies
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
2026-07-03
Published