CVE-2026-8924Disclosure(haxx / curl)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haxx curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-201

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-09); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-09: 1Mentions · 2026-08-01: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-08-01: 1Technical Details · 2026-07-09: 107-0908-01
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-091
Disclosure1
2026-08-011
Patch1
Full discourse2 posts
  • guriguri@guriguri_dW
    Patch

    #IBMAIX ■ Security Bulletin: Multiple vulnerabilities impact AIX due to CURL libcurl (CVE-2026-10536, CVE-2026-11856, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8927, CVE-2026-8932, CVE-2026-9547). https://www.ibm.com/support/pages/node/7281743 沢山あります! 😱

    Post summary

    IBM issued a security bulletin addressing several libcurl-related CVEs affecting AIX, providing patch information through its support page.

    0000051
    123 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - curl "super cookie" injection via PSL bypass (CVE-2026-8924) CVE-2026-8924 is a flaw in curl’s cookie parsing/handling logic that lets a malicious HTTP server set cookies in a way that bypasses the Public Suffix List (PSL) restriction checks. The root cause is improper input validation in cookie domain scoping, allowing crafted cookie attributes to evade PSL enforcement. An attacker exploits this by operating or intercepting an HTTP(S) origin you connect to, then returning a Set-Cookie header that curl accepts and later replays to other unrelated domains during subsequent requests. Real-world impact includes cross-domain cookie injection and leakage, session fixation, and credential/token exposure when curl sends attacker-planted cookies to third-party services. 👉 Affected: curl (versions with vulnerable cookie parsing logic; see vendor advisory for exact range) | Upgrade to fixed curl release once available (No fix yet - treat as suspicious)

    Post summary

    CVE-2026-8924 in curl allows malicious servers to bypass the Public Suffix List and inject cross‑domain cookies, posing risks of session fixation and credential leakage; a patch is pending.

    0000083
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more