CVE-2026-8924

haxx curl: Insertion of Sensitive Information Into Sent Data

criticalEPSS 0.7%

Affected

  • haxx/curl between 7.46.0..8.21.0

Description

A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.

Affected operating systems

  • linux

    ubuntu / curltrusty

Metrics

9.1
Source: nvd-v3
50.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
critical
no public PoC known
0.7 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-03 07:16 UTC
CWE-201

Weakness classes (CWE)

  • CWE-201Base

    Insertion of Sensitive Information Into Sent Data

    The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-15 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Description: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. → A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
    • CWE: CWE-201
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/8xxx/CVE-2026-8924.json">CVE-2026-8924</a>
    • Reference: https://curl.se/docs/CVE-2026-8924.html
  2. CVE Modified2026-09-15 07:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://hackerone.com/reports/3733905
    • Reference: https://hackerone.com/reports/3733905
    • Reference Type: https://hackerone.com/reports/3733905 Types: Exploit, Issue Tracking, Third Party Advisory
  3. Initial Analysis2026-07-07 23:06 UTC· nvd@nist.gov
    • CWE: NVD-CWE-noinfo
    • CPE Configuration: OR *cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* versions from (including) 7.46.0 up to (excluding) 8.21.0
    • Reference Type: curl: https://curl.se/docs/CVE-2026-8924.html Types: Patch, Vendor Advisory
    • Reference Type: curl: https://curl.se/docs/CVE-2026-8924.json Types: Vendor Advisory
  4. New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Affected: curl
    • Description: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
    • Reference: https://curl.se/docs/CVE-2026-8924.html
    • Reference: https://curl.se/docs/CVE-2026-8924.json

Linked advisories