{"id":"CVE-2026-82209","title":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Do…","summary":"When libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Do…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N","cwe":["CWE-201","CWE-501"],"vendor":"haxx","product":"curl","affected":["curl >= 7.46.0, < 8.22.0"],"patched":["curl 8.22.0"],"published":"2026-09-06","updated":"2026-09-15","sourceUpdated":"2026-09-15T07:16:31.233","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209","references":[{"url":"https://curl.se/docs/CVE-2026-82209.html","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://curl.se/docs/CVE-2026-82209.json","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://hackerone.com/reports/3972385","label":"2499f714-1537-4658-8207-48ae4bb9eae9"},{"url":"https://hackerone.com/reports/3972385","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82209.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-82209"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2529207"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-82209"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82209"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat","score-dispute"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-08T18:47:09.259604Z"},"epss":0.0054,"epssPercentile":0.44147,"ingestedAt":"2026-09-07T12:10:14.021Z","scores":{"nvd":8.2,"vendor":3.1},"slug":"CVE-2026-82209","body":"## Overview\n\nWhen libpsl support is enabled, libcurl fails to enforce the Public Suffix\nList boundary check when processing a `Set-Cookie` header where the `Domain`\nattribute explicitly matches an origin host that is itself a public suffix\n(e.g., `Domain=co.uk` set by `co.uk`).\n\nInstead of coercing it into a strict host-only cookie, libcurl saves the\ncookie with wildcard domain scope (`.co.uk`). Consequently, the cookie is\ninappropriately included in subsequent outbound requests or HTTP redirects to\narbitrary sibling subdomains under the same public suffix (e.g.,\n`attacker.co.uk`).\n\n## Affected\n\n- `curl >= 7.46.0, < 8.22.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `curl 8.22.0`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Dev Spaces · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-82209.json)","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":8256,"id":"CVE-2026-82209","ts":1788919995101,"field":"exploit_available","old":"false","new":"true"},{"seq":8255,"id":"CVE-2026-82209","ts":1788919995101,"field":"cvss","old":null,"new":"8.2"},{"seq":8254,"id":"CVE-2026-82209","ts":1788919995101,"field":"severity","old":"none","new":"high"},{"seq":8065,"id":"CVE-2026-82209","ts":1788919281014,"field":"exploit_available","old":"true","new":"false"},{"seq":8064,"id":"CVE-2026-82209","ts":1788919281014,"field":"cvss","old":"8.2","new":null},{"seq":8063,"id":"CVE-2026-82209","ts":1788919281014,"field":"severity","old":"high","new":"none"},{"seq":7874,"id":"CVE-2026-82209","ts":1788916356165,"field":"exploit_available","old":"false","new":"true"},{"seq":7873,"id":"CVE-2026-82209","ts":1788916356165,"field":"cvss","old":null,"new":"8.2"},{"seq":7872,"id":"CVE-2026-82209","ts":1788916356165,"field":"severity","old":"none","new":"high"},{"seq":7683,"id":"CVE-2026-82209","ts":1788915297713,"field":"exploit_available","old":"true","new":"false"},{"seq":7682,"id":"CVE-2026-82209","ts":1788915297713,"field":"cvss","old":"8.2","new":null},{"seq":7681,"id":"CVE-2026-82209","ts":1788915297713,"field":"severity","old":"high","new":"none"},{"seq":7492,"id":"CVE-2026-82209","ts":1788912716821,"field":"exploit_available","old":"false","new":"true"},{"seq":7491,"id":"CVE-2026-82209","ts":1788912716821,"field":"cvss","old":null,"new":"8.2"},{"seq":7490,"id":"CVE-2026-82209","ts":1788912716821,"field":"severity","old":"none","new":"high"},{"seq":7301,"id":"CVE-2026-82209","ts":1788911331646,"field":"exploit_available","old":"true","new":"false"},{"seq":7300,"id":"CVE-2026-82209","ts":1788911331646,"field":"cvss","old":"8.2","new":null},{"seq":7299,"id":"CVE-2026-82209","ts":1788911331646,"field":"severity","old":"high","new":"none"},{"seq":7105,"id":"CVE-2026-82209","ts":1788909078450,"field":"exploit_available","old":"false","new":"true"},{"seq":7104,"id":"CVE-2026-82209","ts":1788909078450,"field":"cvss","old":null,"new":"8.2"},{"seq":7103,"id":"CVE-2026-82209","ts":1788909078450,"field":"severity","old":"none","new":"high"},{"seq":6917,"id":"CVE-2026-82209","ts":1788907391746,"field":"exploit_available","old":"true","new":"false"},{"seq":6916,"id":"CVE-2026-82209","ts":1788907391746,"field":"cvss","old":"8.2","new":null},{"seq":6915,"id":"CVE-2026-82209","ts":1788907391746,"field":"severity","old":"high","new":"none"},{"seq":6719,"id":"CVE-2026-82209","ts":1788905444144,"field":"exploit_available","old":"false","new":"true"},{"seq":6718,"id":"CVE-2026-82209","ts":1788905444144,"field":"cvss","old":null,"new":"8.2"},{"seq":6717,"id":"CVE-2026-82209","ts":1788905444144,"field":"severity","old":"none","new":"high"},{"seq":6537,"id":"CVE-2026-82209","ts":1788903459972,"field":"exploit_available","old":"true","new":"false"},{"seq":6536,"id":"CVE-2026-82209","ts":1788903459972,"field":"cvss","old":"8.2","new":null},{"seq":6535,"id":"CVE-2026-82209","ts":1788903459972,"field":"severity","old":"high","new":"none"},{"seq":6323,"id":"CVE-2026-82209","ts":1788901810776,"field":"exploit_available","old":"false","new":"true"},{"seq":6322,"id":"CVE-2026-82209","ts":1788901810776,"field":"cvss","old":null,"new":"8.2"},{"seq":6321,"id":"CVE-2026-82209","ts":1788901810776,"field":"severity","old":"none","new":"high"},{"seq":6153,"id":"CVE-2026-82209","ts":1788899562370,"field":"exploit_available","old":"true","new":"false"},{"seq":6152,"id":"CVE-2026-82209","ts":1788899562370,"field":"cvss","old":"8.2","new":null},{"seq":6151,"id":"CVE-2026-82209","ts":1788899562370,"field":"severity","old":"high","new":"none"},{"seq":5948,"id":"CVE-2026-82209","ts":1788898179980,"field":"exploit_available","old":"false","new":"true"},{"seq":5947,"id":"CVE-2026-82209","ts":1788898179980,"field":"cvss","old":null,"new":"8.2"},{"seq":5946,"id":"CVE-2026-82209","ts":1788898179980,"field":"severity","old":"none","new":"high"},{"seq":5837,"id":"CVE-2026-82209","ts":1788895711337,"field":"exploit_available","old":"true","new":"false"},{"seq":5836,"id":"CVE-2026-82209","ts":1788895711337,"field":"cvss","old":"8.2","new":null},{"seq":5835,"id":"CVE-2026-82209","ts":1788895711337,"field":"severity","old":"high","new":"none"},{"seq":5743,"id":"CVE-2026-82209","ts":1788894572804,"field":"exploit_available","old":"false","new":"true"},{"seq":5742,"id":"CVE-2026-82209","ts":1788894572804,"field":"cvss","old":null,"new":"8.2"},{"seq":5741,"id":"CVE-2026-82209","ts":1788894572804,"field":"severity","old":"none","new":"high"}]}