CVE-2026-80255
CVE-2026-80255: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityLow3.7
Low [CVE-2026-80255] Information disclosure due to secure cookie attribute bypass
CVE-2026-80255Source published Source updated
A `Set-Cookie:` header using tab (horizontal tab, ASCII code 9) instead of space (ascii code 32) immediately before the `Secure` attribute causes curl to store the cookie without its Secure flag. The cookie might then wrongfully be sent over plaintext HTTP on subsequent requests to the same host. A flaw was found in curl. This misinterpretation can cause a secure cookie to be transmitted over an unencrypted HTTP connection, potentially exposing its contents to an attacker. Red Hat severity: Low — CVSS 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Red Hat Hardened Images; Red Hat Satellite 6. Red Hat lists Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat…
- Affected products in this advisory
- Red Hat Hardened Images
- Red Hat Satellite 6
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- curl-main-8.22.0-0.1.hum1
- RHSA-2026:63161
- Mitigation guidance
- To mitigate this enforce strict HTTPS-only communication (e.g., via HSTS and redirecting all HTTP traffic to HTTPS) across your web infrastructure to ensure curl cannot transmit data over plaintext HTTP. Alternatively, configure reverse proxies or load balancers to sanitize incoming HTTP headers by stripping or replacing horizontal tabs (HTAB) in Set-Cookie headers before they reach the client.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.