Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-8924

Опубликовано: 03 июл. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.21.0~rc2-1package
curlno-dsatrixiepackage
curlpostponedbookwormpackage
curlpostponedbullseyepackage

Примечания

  • https://curl.se/docs/CVE-2026-8924.html

  • Introduced with: https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 (curl-7_46_0)

  • Fixed by: https://github.com/curl/curl/commit/51beed175dbfc37da3113f6acce60c630c070ce8 (rc-8_21_0-1, curl-8_21_0)

EPSS

Процентиль: 43%
0.0056
Низкий

Связанные уязвимости

CVSS3: 9.1
ubuntu
28 дней назад

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

CVSS3: 6.5
redhat
28 дней назад

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

CVSS3: 9.1
nvd
28 дней назад

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

msrc
24 дня назад

trailing dot domain super cookie

CVSS3: 9.1
github
28 дней назад

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

EPSS

Процентиль: 43%
0.0056
Низкий