Skip to content
VulniPulse
Advisory severityLow3.7Red Hat Linux

Low [CVE-2026-80255] Information disclosure due to secure cookie attribute bypass

This low-severity Red Hat Linux advisory covers CVE-2026-80255 affecting Red Hat Hardened Images, Red Hat Satellite 6.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-80255 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.

A flaw was found in curl. This misinterpretation can cause a secure cookie to be transmitted over an unencrypted HTTP connection, potentially exposing its contents to an attacker.

Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-201.

Affected Red Hat products: Red Hat Hardened Images; Red Hat Satellite 6.

Red Hat lists Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Core Services; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6 as not affected.

Red Hat fixing advisory: RHSA-2026:63161.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 7 days ago·verify at source

Fixed versions
  • curl-main-8.22.0-0.1.hum1
  • RHSA-2026:63161

Official advisory · high-confidence parse· fetched 7 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this enforce strict HTTPS-only communication (e.g., via HSTS and redirecting all HTTP traffic to HTTPS) across your web infrastructure to ensure curl cannot transmit data over plaintext HTTP. Alternatively, configure reverse proxies or load balancers to sanitize incoming HTTP headers by stripping or replacing horizontal tabs (HTAB) in Set-Cookie headers before they reach the client.

Official advisory · high-confidence parse· fetched 7 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.