PT-2022-2688 · Libcurl+2 · Libcurl+2

Axel Chong

+1

·

Published

2022-01-27

·

Updated

2026-05-18

·

CVE-2022-27779

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions libcurl versions (affected versions not specified)
Description The issue is related to libcurl's handling of cookies for Top Level Domains (TLDs) when the hostname is provided with a trailing dot. This can allow arbitrary sites to set cookies that then would get sent to a different and unrelated site or domain. The problem arises because the check to prevent cookies from being set on TLDs is broken when the hostname in the URL uses a trailing dot. libcurl's "cookie engine" can be built with or without Public Suffix List awareness, but the rudimentary check in place to prevent cookies from being set on TLDs when PSL support is not provided is ineffective in this scenario.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1837
ALT-PU-2022-1877
ALT-PU-2022-1902
AZL-9908
BDU:2022-03178
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2022-27779
OPENSUSE-SU-2024:12062-1

Affected Products

Alt Linux
Red Os
Libcurl