CVE-2026-80255

NameCVE-2026-80255
DescriptionA `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
curl (PTS)bookworm7.88.1-10+deb12u15fixed
bookworm (security)7.88.1-10+deb12u5fixed
trixie8.14.1-2+deb13u5vulnerable
forky8.21.0-2vulnerable
sid8.22.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
curlsourcebookworm(not affected)
curlsource(unstable)8.22.0-1

Notes

[trixie] - curl <no-dsa> (Minor issue)
[bookworm] - curl <not-affected> (Vulnerable code introduced later)
https://curl.se/docs/CVE-2026-80255.html
Introduced with: https://github.com/curl/curl/commit/1aea05a6c2699e80c75936d58569851555acd603 (curl-8_13_0)
Fixed by: https://github.com/curl/curl/commit/4f6aa41a0145e930e766775dbe860883d350aa0a (curl-8_22_0)

Search for package or bug name: Reporting problems