7.5

CVE-2026-80255

Exploit

secure cookie attribute bypass with tab

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of
space (ascii code 32) immediately before the `Secure` attribute causes curl to
store the cookie without its Secure flag. The cookie might then wrongfully be
sent over plaintext HTTP on subsequent requests to the same host.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Haxx ≫ Curl Version >= 8.13.0 < 8.22.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.119
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-201 Insertion of Sensitive Information Into Sent Data

The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

https://curl.se/docs/CVE-2026-80255.json
Vendor Advisory
https://curl.se/docs/CVE-2026-80255.html
Patch
Vendor Advisory
https://hackerone.com/reports/3972395
Third Party Advisory
Exploit
Mitigation