CVE Vulnerabilities

CVE-2025-9086

Published: Sep 12, 2025 | Modified: Jan 05, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
LOW
  1. A cookie is set using the secure keyword for https://target
  2. curl is redirected to or otherwise made to speak with http://target (same hostname, but using clear text HTTP) using the same cookie set
  3. The same cookie name is set - but with just a slash as path (path=/). Since this site is not secure, the cookie should just be ignored.
  4. A bug in the path comparison logic makes curl read outside a heap buffer boundary

The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.

The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 8 RedHat curl-0:7.61.1-34.el8_10.9 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat curl-0:7.76.1-14.el9_0.12 *
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions RedHat curl-0:7.76.1-23.el9_2.8 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat curl-0:7.76.1-29.el9_4.3 *
Red Hat Enterprise Linux 9.6 Extended Update Support RedHat curl-0:7.76.1-31.el9_6.2 *
Curl Ubuntu devel *
Curl Ubuntu esm-infra-legacy/trusty *
Curl Ubuntu esm-infra/bionic *
Curl Ubuntu esm-infra/focal *
Curl Ubuntu esm-infra/xenial *
Curl Ubuntu jammy *
Curl Ubuntu noble *
Curl Ubuntu plucky *
Curl Ubuntu questing *
Curl Ubuntu upstream *

References