
OtherCVSS 2.5€0
CVE-2026-8924: trailing dot domain super cookie
vegagent
Disclosed on HackerOne · June 24, 2026
Publicly disclosed report · by vegagent
View original on HackerOneSummary:
A PSL-enabled curl build rejects a canonical public suffix cookie such as Domain=co.uk, but accepts the trailing-dot variant Domain=co.uk. when the request host also uses a trailing dot. In the reproduced case, a response from foo.co.uk. sets Set-Cookie: trail=1; Domain=co.uk.; Path=/, and curl later sends Cookie: trail=1 to bar.co.uk. during the same cookie-enabled redirect flow. The canonical control case, foo.co.uk with Domain=co.uk, is rejected as expected. This suggests inconsistent public suffix handling between canonical hostnames and trailing-dot FQDN forms.
Affected version
Reproduced with: curl 8.20.0 (Debian Testing) and 8.21.0-DEV
curl 8.20.0 (x86_64-pc-linux-gnu) libcurl/8.20.0 OpenSSL/3.6.2 zlib/1.3.2 brotli/1.2.0 zstd/1.5.7 libidn2/2.3
.8 libpsl/0.21.5 libssh2/1.11.1 nghttp2/1.69.0 ngtcp2/1.22.1 nghttp3/1.15.0 mit-krb5/1.22.1 OpenLDAP/2.6.10