Skip to main content
QUIETLYTIC
Vulnerability

curl Vulnerability (CVE-2026-82209)

CVE-2026-82209 is a CVSS 8.2 high-severity flaw where libcurl's Public Suffix List check fails to scope a cookie set by a public suffix domain, leaking it to sibling subdomains.

CVE-2026-82209
Threat Level
HIGH
CVSS
8.2
Status
Monitored
Confidence
Medium
Affected Products
curl, libcurl

CVE-2026-82209 is a high-severity (CVSS 3.1 base 8.2) vulnerability in libcurl’s Public Suffix List (PSL) enforcement, when libpsl support is enabled.

What the vulnerability does

Per curl’s own advisory, when a Set-Cookie header’s Domain attribute explicitly matches an origin host that is itself a public suffix (for example, Domain=co.uk set directly by co.uk), libcurl is supposed to coerce that into a strict host-only cookie rather than a wildcard-domain cookie — public suffixes like co.uk are shared by many unrelated registrants, so a cookie scoped to the whole suffix would leak across all of them. The PSL boundary check that’s meant to enforce this fails in that case, and libcurl instead saves the cookie with wildcard scope (.co.uk). The cookie then gets included in subsequent requests or redirects to any sibling subdomain under that suffix — including one an attacker controls, such as attacker.co.uk.

The CVSS vector reflects a network-reachable, low-complexity flaw needing no authentication or user interaction, with a confidentiality impact consistent with cookie/session-token leakage to an attacker-controlled sibling domain.

What we don’t yet have

This record traces to curl’s own advisory and a HackerOne report referenced via NVD; no CISA KEV listing or independent second-source corroboration is present, so confidence is medium. Fixed version information isn’t yet in our ingested data — check curl’s advisory directly.

Why this matters

Applications using libcurl to process cookies from services hosted directly on a public suffix domain (a real, if unusual, hosting pattern) are exposed to cross-tenant cookie leakage — exactly the isolation the Public Suffix List mechanism exists to prevent. Any libcurl-based client interacting with such domains should confirm patch availability.

Frequently Asked Questions

What is CVE-2026-82209? A CVSS 8.2 high-severity vulnerability in libcurl where a cookie set by a domain that is itself a public suffix (e.g. co.uk) is incorrectly scoped with wildcard access instead of being restricted to that exact host.

Is CVE-2026-82209 being actively exploited? No evidence of active exploitation has been reported as of this writing; it is not listed in CISA’s KEV catalog.


Data sourced from the National Vulnerability Database (NVD) and curl’s own advisory (curl.se), aggregated September 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 curl.se

Related intelligence


Analyst tools