CVE-2026-8924
curl
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
- CVSS
- 9.1
- EPSS
- 0.65% 47.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.03