A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 91.00 |
| Exploitation signal(PoC exists) | ×1.20 |
| VPI | 100.00 |
VPI formula vpi-v1
This CVE is referenced in a KISA security bulletin (Korean only).