A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This…
curl·NVD-CWE-noinfo·Published 2026-07-03