Junglewise Threat Intelligence

CVE-2026-8924: curl cookie parsing bypass via trailing dot hostname

CVE-2026-8924 · Severity: info · CVSS 0 · Published 2026-07-03

Technologies: Curl Libcurl, Curl.

Executive brief

A flaw in the curl data transfer tool allows malicious websites to set 'super cookies' that bypass standard security checks. This could allow an attacker to inject cookies that are then sent to unrelated third-party websites, potentially leading to unauthorized data exposure or session manipulation. The issue specifically occurs when hostnames are used with a trailing dot.

Technical details

A vulnerability in curl's cookie handling (CWE-201) arises when a trailing dot is used in a hostname (e.g., 'example.co.uk.'). The parsing logic fails to correctly apply Public Suffix List (PSL) restrictions in this specific scenario, allowing a malicious origin to set cookies for a broader domain scope than permitted. An attacker-controlled server can thus inject cookies that curl will subsequently transmit to unrelated third-party domains. This issue affects curl and libcurl versions 7.46.0 through 8.20.0 and is fixed in version 8.21.0.

Affected products

  • curl curl 7.46.0 to 8.20.0
  • curl libcurl 7.46.0 to 8.20.0

Timeline

  • 2026-05-13: disclosed: Reported to curl project via HackerOne
  • 2026-06-17: other: Distributions notified via distros@openwall
  • 2026-06-24: patched: curl 8.21.0 released with fix
  • 2026-06-24: advisory: Project curl security advisory published
  • 2026-07-03: other: NVD publication date

References