curl 8.21.0 fixes multiple security and correctness issues caused by trailing-dot hostname handling, including CVE-2026-8924, a cookie parsing flaw that lets a malicious HTTP server set "super cookies" for public suffix domains. By abusing hostnames such as example.co.uk., an attacker could bypass curl's Public Suffix List validation and cause curl to later send attacker-set cookies to unrelated third-party domains. The vulnerability affects curl versions 7.46.0 through 8.20.0; builds without PSL support are not protected against this class of issue, and the project recommends upgrading to 8.21.0, applying the patch, or avoiding trailing dots in hostnames.
The release also addresses two additional trailing-dot bugs: curl could treat an IPv4 literal with a trailing dot as a hostname rather than an IP address, potentially allowing an incorrect wildcard TLS certificate match, and hostnames with double trailing dots could trigger internal logic errors including HSTS confusion. curl now bans double-trailing-dot names, and the fixes were coordinated through a June disclosure process after the cookie issue was reported by vegagent on HackerOne and patched by Daniel Stenberg.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
A SecurityWeek report published on June 25, 2026 said curl 8.21.0 fixed 18 vulnerabilities, including CVE-2026-8932, an mTLS connection reuse flaw in libcurl that could allow authentication bypass. The report also said the release addressed four medium-severity and 14 low-severity issues, making it curl's largest single CVE patch batch.
On June 24, 2026, Project curl disclosed CVE-2026-8924, a low-severity cookie parsing flaw that lets a malicious HTTP server set super cookies by abusing trailing-dot domains and bypassing Public Suffix List checks. The advisory states the issue affects curl versions 7.46.0 through 8.20.0 and recommends upgrading to 8.21.0 or applying the patch.
curl 8.21.0 was released on June 24, 2026, fixing three trailing-dot hostname handling issues, including the Public Suffix List cookie-domain flaw tracked as CVE-2026-8924. The fixes also addressed an IPv4-literal trailing-dot issue and problems caused by double trailing dots.
Project curl's advisory says the coordinated disclosure process included notifying distros@openwall about CVE-2026-8924 on June 17, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
16 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcecurl.se
Open sourcecurl.se
Open sourceaisle.com
Open sourcedaniel.haxx.se
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.