secure keyword for https://targethttp://target (same
hostname, but using clear text HTTP) using the same cookie setpath="/").
Since this site is not secure, the cookie should be ignored.The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.
The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.
{
"cna_assigner": "curl",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9086.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.13.0"
},
{
"fixed": "8.14.2"
},
{
"introduced": "1aea05a6c2699e80c75936d58569851555acd603"
},
{
"fixed": "c6ae07c6a541e0e96d0040afb62b45dd37711300"
}
],
"source": "AFFECTED_FIELD"
}
]
}