Public Suffix List Boundary Check Flaw in libcurl by Curl
CVE-2026-82209

Currently unrated

Key Information:

Vendor

Curl

Status
Vendor
CVE Published:
6 September 2026

What is CVE-2026-82209?

A boundary check flaw in libcurl occurs when the Public Suffix List support is enabled. It fails to properly enforce the boundary check for the Domain attribute in Set-Cookie headers that match public suffixes, allowing cookies to be saved with improper domain scope. This can lead to cookies being sent in requests to unauthorized sibling subdomains, thereby exposing sensitive information to potential attacks.

Affected Version(s)

curl 8.21.0

curl 8.20.0

curl 8.19.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Stanislav Fort (Aisle Research)
Daniel Stenberg
.