A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
7.81.0-1ubuntu1.258.5.0-2ubuntu10.108.14.1-2ubuntu1.48.18.0-1ubuntu2.27.47.0-1ubuntu2.19+esm167.58.0-2ubuntu3.24+esm97.68.0-1ubuntu2.25+esm4Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:HI:HA:NCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N