Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-9086— Out of bounds read for cookie path

Quick assessment

Affected
curl curl
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

curl是cURL开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl存在安全漏洞,该漏洞源于路径比较逻辑中存在堆缓冲区边界读取错误,可能导致崩溃或安全cookie被明文站点覆盖。

AI Predicted 5.3 Difficulty: Hard EPSS 1.40% · P72

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 7

VendorProduct Version RangeStatus
curl curl 8.13.0< 8.14.2 affected
8.15.0< 8.16.0 affected
1aea05a6c2699e80c75936d58569851555acd603< c6ae07c6a541e0e96d0040afb62b45dd37711300 affected
8.15.0 affected
8.14.1 affected
8.14.0 affected
8.13.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-9086

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out of bounds read for cookie path
Source: CVE Program / CVE List V5
Vulnerability Description
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with only a slash as path (`path="/"`). Since this site is not secure, the cookie *should* be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path. The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5
Vulnerability Title
curl 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
curl是cURL开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl存在安全漏洞,该漏洞源于路径比较逻辑中存在堆缓冲区边界读取错误,可能导致崩溃或安全cookie被明文站点覆盖。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
curl curl 8.13.0 ~ 8.14.2 -
curl curl 1aea05a6c2699e80c75936d58569851555acd603 ~ c6ae07c6a541e0e96d0040afb62b45dd37711300 -
curl curl 8.15.0 -

II. Public POCs for CVE-2025-9086

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-9086

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-9086

No comments yet


Leave a comment