VDB

CVE-2026-8924

CVE-2026-8924 PUBLISHED CVSS 9.1 CRITICAL

Reported by curl · Published July 3, 2026

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

Risk Scores

CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
curlcurl8.20.0, 8.19.0, 8.18.0
alpinecurl0, 0, 0
curlcurl8.20.0, 8.19.0, 8.18.0

Timeline

  • CVE Published
  • Jun 24, 2026 PoC Published
  • Jul 4, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›