๐Ÿ” CVE Alert

CVE-2025-9086

HIGH 7.5

Out of bounds read for cookie path

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path (`path=\"/\",`). Since this site is not secure, the cookie *should* just be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.

Vendor curl
Product curl
Published Sep 12, 2025
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for curl curl

Be the first to know when new high vulnerabilities affecting curl curl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

curl / curl
8.15.0 โ‰ค 8.15.0 8.14.1 โ‰ค 8.14.1 8.14.0 โ‰ค 8.14.0 8.13.0 โ‰ค 8.13.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
curl.se: https://curl.se/docs/CVE-2025-9086.json curl.se: https://curl.se/docs/CVE-2025-9086.html hackerone.com: https://hackerone.com/reports/3294999 openwall.com: http://www.openwall.com/lists/oss-security/2025/09/10/1 lists.debian.org: https://lists.debian.org/debian-lts-announce/2026/01/msg00002.html cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-089022.html cert-portal.siemens.com: https://cert-portal.siemens.com/productcert/html/ssa-253495.html

Credits

Google Big Sleep Daniel Stenberg