A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.
History

Thu, 10 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1024

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 06 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Curl
Curl curl
Vendors & Products Curl
Curl curl

Sun, 06 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1024

Sun, 06 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.
Title secure cookie attribute bypass with tab
References

cve-icon MITRE

Status: PUBLISHED

Assigner: curl

Published: 2026-09-06T17:48:54.275Z

Updated: 2026-09-08T18:45:49.180Z

Reserved: 2026-08-26T06:25:58.220Z

Link: CVE-2026-80255

cve-icon Vulnrichment

Updated: 2026-09-08T18:45:43.369Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-09-06T18:17:22.623

Modified: 2026-09-08T19:19:54.520

Link: CVE-2026-80255

cve-icon Redhat

No data.