PT-2023-8861 · Curl+11 · Curl+11

Nyymi

·

Published

2023-12-06

·

Updated

2026-04-01

·

CVE-2023-46218

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions cURL (affected versions not specified)
Description This flaw allows a malicious HTTP server to set "super cookies" in cURL that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in cURL's function that verifies a given cookie domain against the Public Suffix List (PSL). For example, a cookie could be set with domain=co.UK when the URL used a lower case hostname curl.co.uk, even though co.uk is listed as a PSL domain.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

ALSA-2024:1129
ALSA-2024:1601
ALT-PU-2023-7837
ALT-PU-2023-7977
ALT-PU-2023-8180
ALT-PU-2023-8316
AZL-32099
AZL-32119
AZL-32126
AZL-34618
AZL-35019
BDU:2024-02420
CESA-2024_1601
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2023-46218
DLA-3692-1
DSA-5587-1
MGASA-2023-0345
OESA-2023-1913
OPENSUSE-SU-2023_4659-1
OPENSUSE-SU-2024:13509-1
RHSA-2024:0428
RHSA-2024:0434
RHSA-2024:0452
RHSA-2024:0585
RHSA-2024:1129
RHSA-2024:1316
RHSA-2024:1601
RHSA-2024_1129
RHSA-2024_1601
RLSA-2024:1601
ROSA-SA-2025-2673
SUSE-SU-2023:4650-1
SUSE-SU-2023:4653-1
SUSE-SU-2023:4659-1
SUSE-SU-2023:4713-1
SUSE-SU-2023_4653-1
SUSE-SU-2023_4659-1
USN-6535-1
USN-6641-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu
Curl