CVE-2026-8924
haxx curl: Insertion of Sensitive Information Into Sent Data
criticalEPSS 0.7%
Affected
- haxx/curl
between 7.46.0..8.21.0
Description
A flaw was found in curl's cookie parsing logic. A malicious HTTP server can exploit this by setting 'super cookies' that bypass the Public Suffix List check. This allows an attacker-controlled origin to inject cookies that curl then transmits to unrelated third-party domains, leading to compromising request integrity.
Affected operating systems
linux
ubuntu / curltrusty
Metrics
Show all metrics
Severity
critical
86.89
no public PoC known
9.1
Published
2026-07-03 07:16 UTC
CWE-201
Weakness classes (CWE)
CWE-201Base
Insertion of Sensitive Information Into Sent Data
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-15 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
- Description: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains. → A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
- CWE: CWE-201
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/8xxx/CVE-2026-8924.json">CVE-2026-8924</a>
- Reference: https://curl.se/docs/CVE-2026-8924.html
- CVE Modified2026-09-15 07:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://hackerone.com/reports/3733905
- Reference: https://hackerone.com/reports/3733905
- Reference Type: https://hackerone.com/reports/3733905 Types: Exploit, Issue Tracking, Third Party Advisory
- Initial Analysis2026-07-07 23:06 UTC· nvd@nist.gov
- CWE: NVD-CWE-noinfo
- CPE Configuration: OR *cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* versions from (including) 7.46.0 up to (excluding) 8.21.0
- Reference Type: curl: https://curl.se/docs/CVE-2026-8924.html Types: Patch, Vendor Advisory
- Reference Type: curl: https://curl.se/docs/CVE-2026-8924.json Types: Vendor Advisory
- New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
- Affected: curl
- Description: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
- Reference: https://curl.se/docs/CVE-2026-8924.html
- Reference: https://curl.se/docs/CVE-2026-8924.json