CRITICALVulnerability

CVE-2026-8924

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

Properties

severity
CRITICAL
score
9.1
epss_score
0.0056
cve_id
CVE-2026-8924
signal_observed_at
2026-09-15T07:22:04+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
published_at
2026-07-03T07:16:24.793
last_modified
2026-09-15T07:16:32.573
epss_percentile
0.44905

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Insertion of Sensitive Information Into Sent Data

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph