This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.

It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

Project Subscriptions

Vendors Products
Fedoraproject Subscribe
Enterprise Linux Subscribe
Jboss Core Services Subscribe
Logging Subscribe
Openshift Data Foundation Subscribe
Rhel Eus Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3692-1 curl security update
Debian DSA Debian DSA DSA-5587-1 curl security update
Ubuntu USN Ubuntu USN USN-6535-1 curl vulnerabilities
Ubuntu USN Ubuntu USN USN-6641-1 curl vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00318}

epss

{'score': 0.00432}


Mon, 30 Jun 2025 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-178

Thu, 13 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
Description This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain. This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-06-30T16:20:37.028Z

Reserved: 2023-10-19T01:00:12.854Z

Link: CVE-2023-46218

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-12-07T01:15:07.160

Modified: 2025-06-30T17:15:29.967

Link: CVE-2023-46218

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-12-06T07:00:00Z

Links: CVE-2023-46218 - Bugzilla

cve-icon OpenCVE Enrichment

No data.