CVE-2026-80255
Last modified
CVE-2026-80255 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.. EPSS estimates a 0.68% chance of exploitation in the next 30 days.
Description
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Haxx | Curl | >= 8.13.0, < 8.22.0 |
References
- https://curl.se/docs/CVE-2026-80255.htmlPatch, Vendor Advisory
- https://curl.se/docs/CVE-2026-80255.jsonVendor Advisory
- https://hackerone.com/reports/3972395Exploit, Mitigation, Third Party Advisory
- https://hackerone.com/reports/3972395Exploit, Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-80255?
How severe is CVE-2026-80255?
How do I fix CVE-2026-80255?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80238Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…9.3
- CVE-2026-80239Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell…2.4
- CVE-2026-8024A remote, unauthenticated attacker may exploit a deserializa…9.8
- CVE-2026-8025Improper neutralization of special elements used in an SQL c…9.8
- CVE-2026-80253An improper physical access control issue exists in ShizenBo…7
- CVE-2026-80254Authorization bypass through user-controlled key issue exist…7.1
- CVE-2026-8026A security flaw has been discovered in FlowiseAI Flowise up …5.3
- CVE-2026-8027A weakness has been identified in FlowiseAI Flowise up to 3.…5.3
- CVE-2026-80274If a BIND resolver sends a query for a DNSSEC-signed authori…7.5
- CVE-2026-8028A vulnerability was detected in FlowiseAI Flowise up to 3.0.…3.7
- CVE-2026-8029The ZTE Smart Life app contains an SQL injection vulnerabili…3.9
- CVE-2026-8030GitLab has remediated an issue in GitLab CE/EE affecting all…4.3
Are you affected by CVE-2026-80255?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
