CVE-2026-8924

Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP5 security update

criticalEPSS 0.6 %

Beschreibung

Ein Fehler im Cookie-Parseteil von cURL ermöglicht einem böswilligen HTTP-Server, 'Super-Cookies' zu setzen, die den Public Suffix List Check umgehen. Dadurch kann ein vom Angreifer kontrollierter Ursprung Cookies injizieren, die cURL anschließend auf andere Drittanbieter-Domains überträgt.

Metriken

Severity
critical
kein öffentlicher PoC bekannt
9.1
Quelle: nvd-v3
44.8 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.6 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-19 13:28 UTC

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. Initial Analysis2026-07-07 23:06 UTC· nvd@nist.gov
    • CWE: NVD-CWE-noinfo
    • CPE Configuration: OR *cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* versions from (including) 7.46.0 up to (excluding) 8.21.0
    • Reference Type: curl: https://curl.se/docs/CVE-2026-8924.html Types: Patch, Vendor Advisory
    • Reference Type: curl: https://curl.se/docs/CVE-2026-8924.json Types: Vendor Advisory
  2. New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Affected: curl
    • Description: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
    • Reference: https://curl.se/docs/CVE-2026-8924.html
    • Reference: https://curl.se/docs/CVE-2026-8924.json

Betroffene Betriebssysteme

  • linux

    ubuntu / curlbionic

  • linux

    ubuntu / curlfocal

  • linux

    ubuntu / curlnoble

  • linux

    ubuntu / curlquesting

  • linux

    ubuntu / curlresolute

  • linux

    ubuntu / curltrusty

  • linux

    ubuntu / curlxenial

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • apache

    http_server2.4.0 – 2.4.68

  • Apple

    iOS18.7.10

  • Apple

    iOS26.6.1

  • Apple

    iPadOS18.7.10

  • Apple

    iPadOS26.6.1

  • Apple

    macOSTahoe 26.6.2

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.55

  • bitnami

    apache

  • haxx

    curl7.30.0 – 8.21.0

  • haxx

    curl7.46.0 – 8.20.0

  • haxx

    curl7.46.0 – 8.21.0

  • haxx

    curl7.69.0 – 8.21.0

  • haxx

    curl8.11.0 – 8.21.0

  • Hitachi Energy

    RTU500< 13.9.1

    gefixt in 13.9.1

  • Splunk

    Splunk Enterprise< 10.0.9

    gefixt in 10.0.9

  • Splunk

    Splunk Enterprise< 10.2.6

    gefixt in 10.2.6

  • Splunk

    Splunk Enterprise< 10.4.2

    gefixt in 10.4.2

  • Splunk

    Splunk Enterprise< 9.4.14

    gefixt in 9.4.14

Quellen & Referenzen

Verknüpfte CVEs

5 weitere CVEs anzeigen

Verknüpfte Empfehlungen

IDCVE-2026-8924