Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-8924 -- CVSS 9.1 Vulnerability Briefing

CVE-2026-8924 | CVSS 9.1 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-8924 is a cookie injection vulnerability in Haxx curl affecting its HTTP cookie parsing logic, where a malicious server can bypass Public Suffix List (PSL) enforcement to set unauthorized cross-domain cookies.

Technical Detail

The flaw exists in curl's cookie parsing routine, which fails to correctly validate domain scope against the Public Suffix List, allowing an attacker-controlled HTTP server to set so-called "super cookies" that are scoped to top-level or shared public domains. An attacker exploiting this would need to position a malicious server in a client's request path, such as through a man-in-the-middle scenario or by operating a legitimate but adversarial web service. Successful exploitation enables session hijacking, credential theft, or authentication bypass against third-party services that share the affected domain scope, depending on the application context in which curl is used.

Exploitation Status

No known exploit exists for this vulnerability at this time. The exploit maturity is assessed as none, and this CVE is not currently listed in the CISA Known Exploited Vulnerabilities catalog. No public proof-of-concept code has been identified as of July 10, 2026.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this vulnerability. Organizations should not interpret the absence of attribution as an indicator of low risk, given the broad deployment of curl across server, client, and embedded environments.

What To Do

Apply the vendor-supplied patch from Haxx for the affected curl release as soon as it becomes available, prioritizing environments where curl is used to handle cookies in authenticated sessions or where it operates against untrusted or third-party HTTP servers. In the interim, consider disabling cookie jar functionality in curl-based applications where persistent cookies are not operationally required, using the --no-sessionid or --cookie-jar suppression options where applicable. Monitor curl release advisories at curl.se and subscribe to the curl security mailing list for patch availability. Detection should focus on anomalous Set-Cookie headers from external servers that attempt to set cookies for broad or unexpected domain scopes in HTTP response traffic.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →