THREAT OPS › Threat News › [NVD] CVE-2026-82209 — When libpsl support is enabled, libcurl fails to enforce the Public Suffix
List boundary check when processing a `Set-Cookie` header where the `Domain`
attribute explicitly matches an origin host that is itself a public suffix
(e.g., `Domain=co.uk` set by `co.uk`).
Instead of co
[NVD] CVE-2026-82209 — When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`). Instead of co
CVE-2026-82209 CVSS: None Published: 2026-09-06T18:17:22.847
When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Domain=co.uk` set by `co.uk`).
Instead of coercing it into a strict host-only cookie, libcurl saves t
Indicators of compromise
- CVE-2026-82209cve
- co.ukdomain
- attacker.co.ukdomain
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-82209