CVE-2026-8924: Haxx Curl
Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
Affected products
- Haxx Curl: from 7.46.0, before 8.21.0 (fixed in 8.21.0)
Published 2026-07-03. Last modified 2026-09-15.