← Back to CVE List
Vulnerability Intelligence Report

CVE-2022-32205

A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to avoid sending crazy large requests (1048576 bytes) and instead returns an error.This denial state might remain for as long as the same cookies are kept, match and haven't expired. Due to cookie matching rules, a server on `foo.example.com` can set cookies that also would match for `bar.example.com`, making it it possible for a "sister server" to effectively cause a denial of service for a sibling site on the same second level domain using this method.

No Active Exploit Signals
CVSS Base Score
4.3
MEDIUM
Exploitability:2.9
Impact Score:1.5
EPSS Probability:26.91%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-770 ↗Allocation of Resources Without Limits or Throttling (CWE-770)

Affected Products & Versions

Vendor Product Affected Versions
haxx curl all
fedoraproject fedora 35
debian debian_linux 11.0
netapp clustered_data_ontap all
netapp element_software all
netapp hci_management_node all
netapp solidfire all
netapp h300s all
netapp h300s_firmware all
netapp h500s all
netapp h500s_firmware all
netapp h700s all
netapp h700s_firmware all
netapp h410s all
netapp h410s_firmware all
apple macos all
siemens scalance_sc622-2c_firmware all
siemens scalance_sc622-2c all
siemens scalance_sc626-2c_firmware all
siemens scalance_sc626-2c all
siemens scalance_sc632-2c_firmware all
siemens scalance_sc632-2c all
siemens scalance_sc636-2c_firmware all
siemens scalance_sc636-2c all
siemens scalance_sc642-2c_firmware all
siemens scalance_sc642-2c all
siemens scalance_sc646-2c_firmware all
siemens scalance_sc646-2c all
splunk universal_forwarder 9.1.0

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
26.915%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityHackerOne · Bug Bounty Provider · USA
Reserved2022-06-01T00:00:00
Published2022-07-07T00:00:00
Last Updated2025-05-05T16:17:03

LINK COPIED TO CLIPBOARD