Skip to main content
QUIETLYTIC
Vulnerability

curl Vulnerability (CVE-2026-80255)

CVE-2026-80255 is a CVSS 7.5 high-severity parsing flaw where a tab character before the Secure attribute in a Set-Cookie header causes libcurl to drop the Secure flag, risking plaintext transmission.

CVE-2026-80255
Threat Level
HIGH
CVSS
7.5
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl

CVE-2026-80255 is a high-severity (CVSS 3.1 base 7.5) cookie-parsing vulnerability in libcurl.

What the vulnerability does

Per curl’s own advisory, a Set-Cookie header that uses a tab character (ASCII code 9) instead of a space (ASCII code 32) immediately before the Secure attribute causes libcurl to store the cookie without its Secure flag. Since the Secure flag is what tells an HTTP client the cookie must only ever be sent over HTTPS, a cookie that loses that flag during parsing might then be wrongfully transmitted over plaintext HTTP on a later request to the same host — exactly the exposure the Secure attribute exists to prevent.

The CVSS vector reflects a network-reachable, low-complexity flaw with a confidentiality impact consistent with a session cookie or other sensitive value being sent in the clear, where a network-positioned attacker could observe it.

What we don’t yet have

This record traces to curl’s own advisory and a HackerOne report via NVD; no CISA KEV listing or independent corroboration is present, so confidence is medium.

Why this matters

This is a parsing edge case rather than a design flaw, but it’s a dangerous one: a server operator setting the Secure attribute correctly on their own cookies has no visibility into whether a client-side parsing bug silently drops that protection, and a single malformed or maliciously crafted Set-Cookie header (whether from the legitimate server or injected by an attacker able to influence response headers) is enough to trigger it. Any application depending on libcurl’s Secure-flag enforcement to keep cookies off plaintext connections should confirm its version against curl’s fix.

Frequently Asked Questions

What is CVE-2026-80255? A CVSS 7.5 high-severity vulnerability in libcurl where a tab character (instead of a space) before the Secure attribute in a Set-Cookie header causes the Secure flag to be dropped, risking plaintext transmission of the cookie.

Is CVE-2026-80255 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools