CVE-2026-8924
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set
'super cookies' that bypass the Public Suffix List check. This enables an
attacker-controlled origin to inject cookies that curl subsequently scopes and
transmits to unrelated third-party domains.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://curl.se/docs/CVE-2026-8924.html, https://curl.se/docs/CVE-2026-8924.json, https://hackerone.com/reports/3733905, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8924.json, https://nvd.nist.gov/vuln/detail/CVE-2026-8924