CVE-2025-9086Patch(debian / curl)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with only a slash as path (`path="/"`). Since this site is not secure, the cookie *should* be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl
  • debian_linux

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-01-31); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
curldebian_linux

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-01-31: 2Mentions · 2026-03-11: 1Mentions · 2026-06-26: 1Mentions · 2026-07-08: 1Patch / Workaround · 2026-01-31: 2Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-01-31: 2Technical Details · 2026-06-26: 1Technical Details · 2026-07-08: 101-3103-1106-2607-08
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-01-312
Patch2
2026-03-111
Disclosure1
2026-06-261
Patch1
2026-07-081
Disclosure1
Full discourse5 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    📌 Security Alert for IT Professionals Rocky Linux has released an important security update for curl (RLSA-2026:1350). This addresses vulnerability CVE-2025-9086 with CVSS score 5.3. Read more: 👉 https://tinyurl.com/3aun86tk #Security #RockyLinux https://t.co/pLcV4UlDkq

    Post summary

    Rocky Linux has issued a security update for curl to address CVE‑2025‑9086, a vulnerability rated CVSS 5.3; the patch can be accessed through the provided link.

    02011104
    1.3K followersView on X
  • CiberBaur@BotBauR
    Patch

    Acaba de confirmarse: Curl ha corregido 18 vulnerabilidades, incluyendo una bug de 25 años, en su mayor lanzamiento de CVE hasta la fecha. Curl, una biblioteca y herramienta de transferencia de datos usada por innumerables aplicaciones, ha remediado varias fallas de seguridad, entre ellas CVE-2024-7264 y CVE-2025-9086, que afectan la autenticación, la seguridad de la memoria y la validación del host en libcurl. El historial de curl muestra que sus incidencias suelen concentrarse en parsing, gestión de memoria y validaciones de seguridad en capas TLS/VTLS. Las fallas corregidas en este lanzamiento pueden tener un impacto significativo en la seguridad de las aplicaciones que dependen de curl. Las correcciones ya fueron implementadas en el proyecto curl y figuran en su historial de cambios. Es crucial que los desarrolladores y administradores de sistemas verifiquen y actualicen sus versiones de curl para evitar posibles ataques. ¿Estás en riesgo? Revisa esto: actualiza a la última versión de curl y verifica si tus aplicaciones dependientes necesitan actualizaciones para asegurarte de que no estás expuesto a estas vulnerabilidades. #Ciberseguridad #CVE #SeguridadDigital #PYMEsMX https://securityaffairs.com/194220/security/curl-fixes-a-25-year-old-bug-in-its-largest-cve-release-yet.html

    Post summary

    El mensaje informa sobre la corrección de 18 vulnerabilidades de Curl, destacando CVE-2024-7264 y CVE-2025-9086, y recomienda actualizar el software para evitar riesgos, sin indicar explotación activa o presencia de PoC.

    01010116
    392 followersView on X
  • GCP Weekly@gcpweekly
    Disclosure

    CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for 10/19

    Post summary

    The post enumerates several CVEs and notes that security fixes are planned for 10/19, but provides no further technical or exploitation details.

    1000097
    1.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - curl cookie path comparison heap out-of-bounds read enables secure cookie override (CVE-2025-9086) curl’s cookie handling has a flaw in its cookie path comparison logic when a Secure cookie set over HTTPS is later followed by a same-name cookie set over cleartext HTTP using path “/”. The root cause is an out-of-bounds heap read due to incorrect bounds checking during cookie path matching/comparison. An attacker can exploit this by inducing a client using libcurl/curl to visit an HTTPS endpoint that sets a Secure cookie, then a related HTTP endpoint that sets a conflicting cookie name/path, requiring network/MITM positioning or control of served content/domains in the request chain. Impact ranges from denial of service via crash to potential session integrity compromise if the insecure cookie incorrectly overrides the Secure cookie based on adjacent heap memory contents. 👉 Affected: curl (versions TBD) | Upgrade to No fix yet - treat as suspicious

    Post summary

    The text announces CVE-2025-9086, detailing an out-of-bounds heap read in curl’s cookie handling and its potential impact, but does not provide PoC, exploit, or patch information.

    0000071
    246 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    📌 Security Alert for IT Professionals Rocky Linux has released an important security update for curl (RLSA-2026:1350). This addresses vulnerability CVE-2025-9086 with CVSS score 5.3. Read more:👉 https://tinyurl.com/3aun86tk #Security #RockyLinux https://t.co/yrE9O8r5kb

    Post summary

    The post announces Rocky Linux’s patch for curl addressing CVE-2025-9086 with a CVSS score of 5.3.

    0000096
    1.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Apphaxxcurl---

Explore more