{"api_version":"1","generated_at":"2026-06-10T20:54:05+00:00","cve":"CVE-2025-9086","urls":{"html":"https://cve.report/CVE-2025-9086","api":"https://cve.report/api/cve/CVE-2025-9086.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-9086","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-9086"},"summary":{"title":"Out of bounds read for cookie path","description":"1. A cookie is set using the `secure` keyword for `https://target` \n 2. curl is redirected to or otherwise made to speak with `http://target` (same \n   hostname, but using clear text HTTP) using the same cookie set \n 3. The same cookie name is set - but with just a slash as path (`path=\\\"/\\\",`).\n   Since this site is not secure, the cookie *should* just be ignored.\n4. A bug in the path comparison logic makes curl read outside a heap buffer\n   boundary\n\nThe bug either causes a crash or it potentially makes the comparison come to\nthe wrong conclusion and lets the clear-text site override the contents of the\nsecure cookie, contrary to expectations and depending on the memory contents\nimmediately following the single-byte allocation that holds the path.\n\nThe presumed and correct behavior would be to plainly ignore the second set of\nthe cookie since it was already set as secure on a secure host so overriding\nit on an insecure host should not be okay.","state":"PUBLISHED","assigner":"curl","published_at":"2025-09-12 06:15:44","updated_at":"2026-06-02 14:16:40"},"problem_types":["CWE-125","CWE-125 Out-of-bounds Read"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}}],"references":[{"url":"https://curl.se/docs/CVE-2025-9086.json","name":"https://curl.se/docs/CVE-2025-9086.json","refsource":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-089022.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-089022.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://curl.se/docs/CVE-2025-9086.html","name":"https://curl.se/docs/CVE-2025-9086.html","refsource":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/10/1","name":"http://www.openwall.com/lists/oss-security/2025/09/10/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-253495.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-253495.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00002.html","name":"https://lists.debian.org/debian-lts-announce/2026/01/msg00002.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://hackerone.com/reports/3294999","name":"https://hackerone.com/reports/3294999","refsource":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Exploit","Issue Tracking","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-9086","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9086","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.15.0 8.15.0 semver","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.14.1 8.14.1 semver","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.14.0 8.14.0 semver","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.13.0 8.13.0 semver","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"RUGGEDCOM RST2428P","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"RUGGEDCOM RST2428P","version":"affected V4.0 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XCH328","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XCM324","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XCM328","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XCM332","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRH334 (24 V DC, 8xFO, CC)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (230 V AC, 12xFO)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (230 V AC, 8xFO)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (24 V DC, 12xFO)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (24 V DC, 8xFO)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (2x230 V AC, 12xFO)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (2x230 V AC, 8xFO)","version":"affected V3.3 custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+)","version":"affected V3.3 custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Google Big Sleep","lang":"en"},{"source":"CNA","value":"Daniel Stenberg","lang":"en"}],"nvd_cpes":[{"cve_year":"2025","cve_id":"9086","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2025","cve_id":"9086","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"curl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"9086","cve":"CVE-2025-9086","epss":"0.003640000","percentile":"0.587940000","score_date":"2026-06-08","updated_at":"2026-06-09 00:12:52"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},{"other":{"content":{"id":"CVE-2025-9086","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-09-12T17:15:47.921625Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-09-12T17:16:20.317Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2026-01-05T02:47:38.406Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2025/09/10/1"},{"url":"https://lists.debian.org/debian-lts-announce/2026/01/msg00002.html"}],"title":"CVE Program Container"},{"affected":[{"defaultStatus":"unknown","product":"RUGGEDCOM RST2428P","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"RUGGEDCOM RST2428P","vendor":"Siemens","versions":[{"lessThan":"V4.0","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XCH328","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XCM324","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XCM328","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XCM332","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRH334 (24 V DC, 8xFO, CC)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (230 V AC, 12xFO)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (230 V AC, 8xFO)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (230V AC, 2x10G, 24xSFP, 8xSFP+)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (24 V DC, 12xFO)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (24 V DC, 8xFO)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (24V DC, 2x10G, 24xSFP, 8xSFP+)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (2x230 V AC, 12xFO)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (2x230 V AC, 8xFO)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SCALANCE XRM334 (2x230V AC, 2x10G, 24xSFP, 8xSFP+)","vendor":"Siemens","versions":[{"lessThan":"V3.3","status":"affected","version":"0","versionType":"custom"}]}],"providerMetadata":{"dateUpdated":"2026-06-02T12:59:46.514Z","orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP"},"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-089022.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-253495.html"}],"x_adpType":"supplier"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"lessThanOrEqual":"8.15.0","status":"affected","version":"8.15.0","versionType":"semver"},{"lessThanOrEqual":"8.14.1","status":"affected","version":"8.14.1","versionType":"semver"},{"lessThanOrEqual":"8.14.0","status":"affected","version":"8.14.0","versionType":"semver"},{"lessThanOrEqual":"8.13.0","status":"affected","version":"8.13.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Google Big Sleep"},{"lang":"en","type":"remediation developer","value":"Daniel Stenberg"}],"descriptions":[{"lang":"en","value":"1. A cookie is set using the `secure` keyword for `https://target` \n 2. curl is redirected to or otherwise made to speak with `http://target` (same \n   hostname, but using clear text HTTP) using the same cookie set \n 3. The same cookie name is set - but with just a slash as path (`path=\\\"/\\\",`).\n   Since this site is not secure, the cookie *should* just be ignored.\n4. A bug in the path comparison logic makes curl read outside a heap buffer\n   boundary\n\nThe bug either causes a crash or it potentially makes the comparison come to\nthe wrong conclusion and lets the clear-text site override the contents of the\nsecure cookie, contrary to expectations and depending on the memory contents\nimmediately following the single-byte allocation that holds the path.\n\nThe presumed and correct behavior would be to plainly ignore the second set of\nthe cookie since it was already set as secure on a secure host so overriding\nit on an insecure host should not be okay."}],"problemTypes":[{"descriptions":[{"description":"CWE-125 Out-of-bounds Read","lang":"en"}]}],"providerMetadata":{"dateUpdated":"2026-01-08T09:51:46.552Z","orgId":"2499f714-1537-4658-8207-48ae4bb9eae9","shortName":"curl"},"references":[{"name":"json","url":"https://curl.se/docs/CVE-2025-9086.json"},{"name":"www","url":"https://curl.se/docs/CVE-2025-9086.html"},{"name":"issue","url":"https://hackerone.com/reports/3294999"}],"title":"Out of bounds read for cookie path"}},"cveMetadata":{"assignerOrgId":"2499f714-1537-4658-8207-48ae4bb9eae9","assignerShortName":"curl","cveId":"CVE-2025-9086","datePublished":"2025-09-12T05:10:03.815Z","dateReserved":"2025-08-16T05:40:23.800Z","dateUpdated":"2026-06-02T12:59:46.514Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-09-12 06:15:44","lastModifiedDate":"2026-06-02 14:16:40","problem_types":["CWE-125","CWE-125 Out-of-bounds Read"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*","versionStartIncluding":"8.13.0","versionEndExcluding":"8.16.0","matchCriteriaId":"4979D5F1-8D49-4EC0-AC6B-230636A10C34"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*","matchCriteriaId":"FA6FEEC2-9F11-4643-8827-749718254FED"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"9086","Ordinal":"1","Title":"Out of bounds read for cookie path","CVE":"CVE-2025-9086","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"9086","Ordinal":"1","NoteData":"1. A cookie is set using the `secure` keyword for `https://target` \n 2. curl is redirected to or otherwise made to speak with `http://target` (same \n   hostname, but using clear text HTTP) using the same cookie set \n 3. The same cookie name is set - but with just a slash as path (`path=\\\"/\\\",`).\n   Since this site is not secure, the cookie *should* just be ignored.\n4. A bug in the path comparison logic makes curl read outside a heap buffer\n   boundary\n\nThe bug either causes a crash or it potentially makes the comparison come to\nthe wrong conclusion and lets the clear-text site override the contents of the\nsecure cookie, contrary to expectations and depending on the memory contents\nimmediately following the single-byte allocation that holds the path.\n\nThe presumed and correct behavior would be to plainly ignore the second set of\nthe cookie since it was already set as secure on a secure host so overriding\nit on an insecure host should not be okay.","Type":"Description","Title":"Out of bounds read for cookie path"}]}}}