1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the sam…
高危 CVSS 7.5
摘要
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with only a slash as path (`path="/"`). Since this site is not secure, the cookie *should* be ignored. 4. A bug in the path comparison logic makes curl read outside a heap buffer boundary The bug either causes a crash or it potentially makes t…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
- :
数据来源
- NVD DATABASE
原始链接
- https://curl.se/docs/CVE-2025-9086.html Patch
- https://curl.se/docs/CVE-2025-9086.json Vendor Advisory
- https://hackerone.com/reports/3294999 Exploit
- http://www.openwall.com/lists/oss-security/2025/09/10/1 Mailing List
- https://lists.debian.org/debian-lts-announce/2026/01/msg00002.html Mailing List
- https://cert-portal.siemens.com/productcert/html/ssa-089022.html
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
时间线
- nvd_ingest NVD