Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2025-9086
curl curl — Out of bounds read for cookie path
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0140 71.4 —
AFFECTED
Product Versions Fixed
curl 8.13.0 – —
curl 1aea05a6c2699e80c75936d58569851555acd603 – —
curl 8.15.0 – —
TIMELINE
Aug 16 Reserved by curl
Sep 12 Published (CNA: curl)
Sep 14 EXPLOIT PUBLISHED — CVE-2025-9086 (curl). Public exploit reference added.
Description
1. A cookie is set using the `secure` keyword for `https://target`
2. curl is redirected to or otherwise made to speak with `http://target` (same
hostname, but using clear text HTTP) using the same cookie set
3. The same cookie name is set - but with only a slash as path (`path="/"`).
Since this site is not secure, the cookie *should* be ignored.
4. A bug in the path comparison logic makes curl read outside a heap buffer
boundary
The bug either causes a crash or it potentially makes the comparison come to
the wrong conclusion and lets the clear-text site override the contents of the
secure cookie, contrary to expectations and depending on the memory contents
immediately following the single-byte allocation that holds the path.
The presumed and correct behavior would be to plainly ignore the second set of
the cookie since it was already set as secure on a secure host so overriding
it on an insecure host should not be okay.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 16, 2025 | Reserved | Reserved by curl |
| September 12, 2025 | Published | Published (CNA: curl) |
| September 14, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2025-9086 (curl). Public exploit reference added. |
Affected
Affected products and packages — 3 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| curl | curl | — | 8.13.0 | — |
| curl | curl | — | 1aea05a6c2699e80c75936d58569851555acd603 | — |
| curl | curl | — | 8.15.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-9086 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.