Low [CVE-2026-80255] Information disclosure due to secure cookie attribute bypass
This low-severity Red Hat Linux advisory covers CVE-2026-80255 affecting Red Hat Hardened Images, Red Hat Satellite 6.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host.
A flaw was found in curl. This misinterpretation can cause a secure cookie to be transmitted over an unencrypted HTTP connection, potentially exposing its contents to an attacker.
Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-201.
Affected Red Hat products: Red Hat Hardened Images; Red Hat Satellite 6.
Red Hat lists Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat JBoss Core Services; Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces; Red Hat Satellite 6 as not affected.
Red Hat fixing advisory: RHSA-2026:63161.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 7 days ago·verify at source
- curl-main-8.22.0-0.1.hum1
- RHSA-2026:63161
Official advisory · high-confidence parse· fetched 7 days ago·verify at source
Mitigation checklist
- To mitigate this enforce strict HTTPS-only communication (e.g., via HSTS and redirecting all HTTP traffic to HTTPS) across your web infrastructure to ensure curl cannot transmit data over plaintext HTTP. Alternatively, configure reverse proxies or load balancers to sanitize incoming HTTP headers by stripping or replacing horizontal tabs (HTAB) in Set-Cookie headers before they reach the client.
Official advisory · high-confidence parse· fetched 7 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.