Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80255— secure cookie attribute bypass with tab

Quick assessment

Affected
curl curl
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 8.21.0版本、8.20.0版本、8.19.0版本、8.18.0版本、8.17.0版本、8.16.0版本、8.15.0版本、8.14.1版本、8.14.0版本和8.13.0版本存在信息泄露漏洞,该漏洞源于Set-Cookie头中Secure属性前使用制表符而非空格,导致curl存储Cookie时未设置Secure标志,可能使Cookie在后续请求中通过明文HTTP发送。

AI Predicted 6.1 Difficulty: Moderate EPSS 0.68% · P51

Possible ATT&CK Techniques 1 AI

T1013

Affected Version Matrix 15

VendorProduct Version RangeStatus
curl curl 8.13.0< 8.14.2 affected
8.15.0< 8.16.1 affected
8.17.0< 8.20.1 affected
8.21.0< 8.22.0 affected
1aea05a6c2699e80c75936d58569851555acd603< 4f6aa41a0145e930e766775dbe860883d350aa0a affected
8.21.0 affected
8.20.0 affected
8.19.0 affected
… +7 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80255

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
secure cookie attribute bypass with tab
Source: CVE Program / CVE List V5
Vulnerability Description
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
通过发送数据的信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
curl 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 8.21.0版本、8.20.0版本、8.19.0版本、8.18.0版本、8.17.0版本、8.16.0版本、8.15.0版本、8.14.1版本、8.14.0版本和8.13.0版本存在信息泄露漏洞,该漏洞源于Set-Cookie头中Secure属性前使用制表符而非空格,导致curl存储Cookie时未设置Secure标志,可能使Cookie在后续请求中通过明文HTTP发送。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
curl curl 8.13.0 ~ 8.14.2 -
curl curl 1aea05a6c2699e80c75936d58569851555acd603 ~ 4f6aa41a0145e930e766775dbe860883d350aa0a -
curl curl 8.21.0 -

II. Public POCs for CVE-2026-80255

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80255

登录查看更多情报信息。

Vendor Advisories for CVE-2026-80255 (2)

Proof of Concept for CVE-2026-80255 (1)

Same Patch Batch · curl · 2026-09-06 · 9 CVEs total

CVE-2026-82208 wolfSSL CA-cache hit overrides callback
CVE-2026-82209 domain-scoped PSL domain cookie
CVE-2026-18924 HTTP/2 server push UAF
CVE-2026-19931 Negotiate ambient user conn reuse
CVE-2026-80231 native CA store conn reuse
CVE-2026-80229 OpenSSL provider use-after-free
CVE-2026-80230 OpenSSL pinning bypass
CVE-2026-13608 OpenLDAP SASL authentication bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-80255

No comments yet


Leave a comment