{"id":"CURL-CVE-2026-80255","summary":"secure cookie attribute bypass with tab","details":"A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of\nspace (ascii code 32) immediately before the `Secure` attribute causes curl to\nstore the cookie without its Secure flag. The cookie might then wrongfully be\nsent over plaintext HTTP on subsequent requests to the same host.","aliases":["CVE-2026-80255"],"modified":"2026-09-03T02:01:08.203846Z","published":"2026-09-02T08:00:00Z","database_specific":{"issue":"https://hackerone.com/reports/3972395","last_affected":"8.21.0","package":"curl","severity":"Low","www":"https://curl.se/docs/CVE-2026-80255.html","CWE":{"desc":"Information Exposure Through Sent Data","id":"CWE-201"},"URL":"https://curl.se/docs/CVE-2026-80255.json","affects":"both"},"affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"8.13.0"},{"fixed":"8.22.0"}]},{"type":"GIT","repo":"https://github.com/curl/curl.git","events":[{"introduced":"1aea05a6c2699e80c75936d58569851555acd603"},{"fixed":"4f6aa41a0145e930e766775dbe860883d350aa0a"}]}],"versions":["8.21.0","8.20.0","8.19.0","8.18.0","8.17.0","8.16.0","8.15.0","8.14.1","8.14.0","8.13.0","rc-8_22_0-3","rc-8_22_0-2","rc-8_22_0-1","curl-8_21_0","rc-8_21_0-3","rc-8_21_0-2","rc-8_21_0-1","curl-8_20_0","rc-8_20_0-3","rc-8_20_0-2","rc-8_20_0-1","curl-8_19_0","rc-8_19_0-3","rc-8_19_0-2","rc-8_19_0-1","curl-8_18_0","rc-8_18_0-3","rc-8_18_0-2","rc-8_18_0-1","curl-8_17_0","curl-8_16_0","curl-8_15_0","curl-8_14_1","curl-8_14_0","curl-8_13_0"],"database_specific":{"source":"https://curl.se/docs/CURL-CVE-2026-80255.json","vanir_signatures_modified":"2026-09-03T02:01:08Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/curl/curl.git/commit/4f6aa41a0145e930e766775dbe860883d350aa0a","target":{"function":"parse_cookie_header","file":"lib/cookie.c"},"deprecated":false,"digest":{"function_hash":"156248508838678620174316832758863728670","length":1807},"id":"CURL-CVE-2026-80255-1976306a","signature_type":"Function"},{"id":"CURL-CVE-2026-80255-d501f15b","signature_type":"Line","signature_version":"v1","source":"https://github.com/curl/curl.git/commit/4f6aa41a0145e930e766775dbe860883d350aa0a","target":{"file":"lib/cookie.c"},"deprecated":false,"digest":{"line_hashes":["205816004684899671603710379302867268706","18514482557387433468133516516178791980","274291864640093038674042589109486318957","147342966625047719758808367123869032769"],"threshold":0.9}}]}}],"schema_version":"1.9.0","credits":[{"name":"Stanislav Fort (Aisle Research)","type":"FINDER"},{"name":"Daniel Stenberg","type":"REMEDIATION_DEVELOPER"}]}