curl是瑞典curl团队开源的一款用于从服务器传输数据或向服务器传输数据的工具。 curl 7.46.0版本至8.21.0版本存在信息泄露漏洞,该漏洞源于启用libpsl支持时,处理Set-Cookie标头中Domain属性为公共后缀(如co.uk)的内容时未正确执行公共后缀列表边界检查,导致Cookie被存储为通配符域范围(.co.uk),可能被错误发送到同一公共后缀下的任意兄弟子域(如attacker.co.uk),造成Cookie意外泄露或未授权使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82208 | wolfSSL CA-cache hit overrides callback | |
| CVE-2026-18924 | HTTP/2 server push UAF | |
| CVE-2026-19931 | Negotiate ambient user conn reuse | |
| CVE-2026-80231 | native CA store conn reuse | |
| CVE-2026-80229 | OpenSSL provider use-after-free | |
| CVE-2026-80230 | OpenSSL pinning bypass | |
| CVE-2026-80255 | secure cookie attribute bypass with tab | |
| CVE-2026-13608 | OpenLDAP SASL authentication bypass |
No comments yet