A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set super cookies that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Curl | Haxx | 7.46.0 (including) | 8.21.0 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | curl-0:8.12.1-4.el10_2.6 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | curl-0:8.12.1-1.el10_0.10 | * |
| Red Hat Hardened Images | RedHat | curl-main-8.21.0-0.1.hum1 | * |
| Red Hat Hardened Images | RedHat | rust-main-1.96.1-1.hum1 | * |
| Curl | Ubuntu | devel | * |
| Curl | Ubuntu | esm-infra-legacy/xenial | * |
| Curl | Ubuntu | esm-infra/bionic | * |
| Curl | Ubuntu | esm-infra/focal | * |
| Curl | Ubuntu | jammy | * |
| Curl | Ubuntu | noble | * |
| Curl | Ubuntu | questing | * |
| Curl | Ubuntu | resolute | * |
| Curl | Ubuntu | upstream | * |