libcurl is widely deployed; this cookie-scope bypass can leak session/auth cookies across domains, affecting many services and clients.
CVE-2026-82209
libcurl cookie boundary bypass leaks cookies to sibling subdomains.
Is CVE-2026-82209 being exploited?
Not confirmed. CVE-2026-82209 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.54% probability of exploitation in the next 30 days.
How severe is CVE-2026-82209?
CVE-2026-82209 is rated High with a CVSS score of 8.2. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-82209?
Yes. A fix has been recorded for CVE-2026-82209. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-82209 affect?
CVE-2026-82209 affects libcurl (with libpsl enabled), Applications/services using libcurl for HTTP, Embedded devices bundling libcurl. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-82209?
Upgrade libcurl; if unavailable disable libpsl or reject public-suffix cookies.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Cookies set for a public suffix are saved with wildcard scope, allowing attacker-controlled sibling subdomains to receive cookies and enable session hijack or account takeover.
Immediate action required
- affected<= 8.21.0
- affected<= 8.20.0
- affected<= 8.19.0
- affected<= 8.18.0
- affected<= 8.17.0
- affected<= 8.16.0
- affected<= 8.15.0
- affected<= 8.14.1
- affected<= 8.14.0
- affected<= 8.13.0
- affected<= 8.12.1
- affected<= 8.12.0
- affected<= 8.11.1
- affected<= 8.11.0
- affected<= 8.10.1
- affected<= 8.10.0
- affected<= 8.9.1
- affected<= 8.9.0
- affected<= 8.8.0
- affected<= 8.7.1
- affected<= 8.7.0
- affected<= 8.6.0
- affected<= 8.5.0
- affected<= 8.4.0
- affected<= 8.3.0
- affected<= 8.2.1
- affected<= 8.2.0
- affected<= 8.1.2
- affected<= 8.1.1
- affected<= 8.1.0
- affected<= 8.0.1
- affected<= 8.0.0
- affected<= 7.88.1
- affected<= 7.88.0
- affected<= 7.87.0
- affected<= 7.86.0
- affected<= 7.85.0
- affected<= 7.84.0
- affected<= 7.83.1
- affected<= 7.83.0
- affected<= 7.82.0
- affected<= 7.81.0
- affected<= 7.80.0
- affected<= 7.79.1
- affected<= 7.79.0
- affected<= 7.78.0
- affected<= 7.77.0
- affected<= 7.76.1
- affected<= 7.76.0
- affected<= 7.75.0
- affected<= 7.74.0
- affected<= 7.73.0
- affected<= 7.72.0
- affected<= 7.71.1
- affected<= 7.71.0
- affected<= 7.70.0
- affected<= 7.69.1
- affected<= 7.69.0
- affected<= 7.68.0
- affected<= 7.67.0
- affected<= 7.66.0
- affected<= 7.65.3
- affected<= 7.65.2
- affected<= 7.65.1
- affected<= 7.65.0
- affected<= 7.64.1
- affected<= 7.64.0
- affected<= 7.63.0
- affected<= 7.62.0
- affected<= 7.61.1
- affected<= 7.61.0
- affected<= 7.60.0
- affected<= 7.59.0
- affected<= 7.58.0
- affected<= 7.57.0
- affected<= 7.56.1
- affected<= 7.56.0
- affected<= 7.55.1
- affected<= 7.55.0
- affected<= 7.54.1
- affected<= 7.54.0
- affected<= 7.53.1
- affected<= 7.53.0
- affected<= 7.52.1
- affected<= 7.52.0
- affected<= 7.51.0
- affected<= 7.50.3
- affected<= 7.50.2
- affected<= 7.50.1
- affected<= 7.50.0
- affected<= 7.49.1
- affected<= 7.49.0
- affected<= 7.48.0
- affected<= 7.47.1
- affected<= 7.47.0
- affected<= 7.46.0
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.