Back to search
CVE-2022-35252
Published: Sep 23, 2022
Modified: May 5, 2025
PUBLISHED
Description
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.
| Vendor | Product | Versions |
|---|---|---|
n/a | https://github.com/curl/curl | affected Fixed in curl 7.85.0 |
Weaknesses (CWE)
References
GLSA-202212-01
vendor-advisory
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now