Public Suffix List Boundary Check Flaw in libcurl by Curl
CVE-2026-82209
Currently unrated
What is CVE-2026-82209?
A boundary check flaw in libcurl occurs when the Public Suffix List support is enabled. It fails to properly enforce the boundary check for the Domain attribute in Set-Cookie headers that match public suffixes, allowing cookies to be saved with improper domain scope. This can lead to cookies being sent in requests to unauthorized sibling subdomains, thereby exposing sensitive information to potential attacks.
Affected Version(s)
curl 8.21.0
curl 8.20.0
curl 8.19.0
