CVE-2023-46218Haxx · Curl
Vulnerability data via NVD (ingested)
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2023-46218product:"Haxx Curl"http.html:"Curl"More intel sources (5)
vuln:CVE-2023-46218vulnerabilities.cve_id: CVE-2023-46218CVE-2023-46218CVE-2023-46218"CVE-2023-46218" exploit -site:nvd.nist.gov