THREAT OPS › Threat News › [NVD] CVE-2025-9086 (HIGH 7.5) — 1. A cookie is set using the `secure` keyword for `https://target`
2. curl is redirected to or otherwise made to speak with `http://target` (same
hostname, but using clear text HTTP) using the same cookie set
3. The same cookie name is set - but with only a slash as path (`pat
[NVD] CVE-2025-9086 (HIGH 7.5) — 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with only a slash as path (`pat
CVE-2025-9086 CVSS: 7.5 HIGH Published: 2025-09-12T06:15:44.100
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with only a slash as path (`path="/"`). Since this site is not secure, the cookie *
Indicators of compromise
- CVE-2025-9086cve
- https://target`url
- http://target`url
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-9086