This issue requires an assignee. Since you haven't specified one, we've assigned TestManager as the default assignee for this issue.


issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, opengauss评分, 受影响版本排查(受影响/不受影响))不能省略,省略后cve-manager将无法正常解析填写内容.
影响性分析说明:
漏洞评分(opengauss评分):
BaseScore: x.x(浮点格式)
Vector:
受影响版本排查(受影响/不受影响):
1.master:


Welcome To openGauss Community
Hey @opengauss_bot , thanks for your contribution to the community.
Bot Usage Manual
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands.
Contact Guide
If you have any questions, please contact the SIG: StorageEngine ,
and any of the maintainers: @CarrotGo, @chendong76, @chenxiaobin19, @congzhou2603, @dodders, @hwworkholic, @jemappellehc, @muyulinzhong, @quemingjian, @shenzheng4, @shirley_zhengx, @superlchf, @totaj, @wlff234, @ywzq1161327784 ,
and any of the committers: @Igali, @bihua111, @cailei19, @h_ray, @levy53071, @libiao2024, @lihaixiao, @mrzack, @wangfeihuo, @wuyuechuan, @xiong_xjun, @zhangfengzhi123, @zhangxubo, @zjh_hw .


影响性分析说明:
CVE-2026-8924影响curl 7.46.0至8.20.0,master和6.0.0均使用curl 7.78.0,位于受影响范围;当curl访问带尾点的主机名且恶意HTTP服务器设置同样带尾点的Cookie Domain时,Cookie解析逻辑可能绕过Public Suffix List检查并设置覆盖公共后缀的超级Cookie,导致该Cookie随后被发送给不相关的第三方域名;两个分支已回移CVE-2026-8924.patch,在执行PSL检查前规范化并移除域名尾点,并由build.sh在构建时应用补丁完成修复。
漏洞评分(opengauss评分):
BaseScore: 9.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
受影响版本排查(受影响/不受影响):
1.master:受影响
2.6.0.0:受影响


经过cve-manager解析,已分析的内容如下表所示:
| 状态 | 分析项目 | 内容 |
|---|---|---|
| 已分析 | 影响性分析说明 | CVE-2026-8924影响curl 7.46.0至8.20.0,master和6.0.0均使用curl 7.78.0,位于受影响范围;当curl访问带尾点的主机名且恶意HTTP服务器设置同样带尾点的Cookie Domain时,Cookie解析逻辑可能绕过Public Suffix List检查并设置覆盖公共后缀的超级Cookie,导致该Cookie随后被发送给不相关的第三方域名;两个分支已回移CVE-2026-8924.patch,在执行PSL检查前规范化并移除域名尾点,并由build.sh在构建时应用补丁完成修复。 |
| 已分析 | BaseScore | 9.1 |
| 已分析 | Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 已分析 | 受影响版本排查 | master:受影响 |
请确认分析内容的准确性, 确认无误后, 您可以进行后续步骤, 否则您可以继续分析.


pr已合入,问题单关闭。


一、漏洞信息
漏洞编号:CVE-2026-8924
漏洞归属组件:curl, https://gitcode.com/opengauss/openGauss-third_party
漏洞归属的版本:7.78.0
CVSS分值:
BaseScore: N/A None
Vector: N/A
漏洞简述:
[_x27;Hello friends,_x27;, _x27;CVE-2026-8286: wrong STARTTLS connection reuse (LOW)_x27;, _x27;CVE-2026-8458: wrong reuse for different services (LOW)_x27;, _x27;CVE-2026-8924: traling dot domain super cookie (LOW)_x27;, _x27;CVE-2026-8925: SASL double-free (MEDIUM)_x27;, _x27;CVE-2026-8926: password leak with netrc and user in URL (LOW)_x27;, _x27;CVE-2026-8927: env-set cross-proxy Digest auth state leak (MEDIUM)_x27;, _x27;CVE-2026-8932: incomplete mTLS config matching in conn reuse (LOW)_x27;, _x27;CVE-2026-9079: stale proxy password leak (MEDIUM)_x27;, _x27;CVE-2026-9080: UAF after pause in socket callback (LOW)_x27;, _x27;CVE-2026-9545: exposing HTTP/3 early data (LOW)_x27;, _x27;CVE-2026-9546: sending old referer (LOW)_x27;, _x27;CVE-2026-9547: SSH improper host validation (LOW)_x27;, _x27;CVE-2026-10536: HTTP/2 stream-dependency tree UAF (LOW)_x27;, _x27;CVE-2026-11352: QUIC zero-length UDP datagrams busy-loop (LOW)_x27;, _x27;CVE-2026-11564: Native CA trust persist (LOW)_x27;, _x27;CVE-2026-11586: WS Auto-PONG memory exhaustion (LOW)_x27;, _x27;CVE-2026-11856: cross-origin Digest auth state leak (MEDIUM)_x27;, _x27;CVE-2026-12064: proto-default skips SSH verification (LOW)_x27;, _x27;--\n\n / daniel.haxx.se ||_x27;]
漏洞公开时间:2026-07-03 15:16:24
漏洞创建时间:2026-07-04 20:40:44
漏洞详情参考链接:
https://nvd.nist.gov/vuln/detail/CVE-2026-8924
漏洞补丁信息:
二、漏洞分析结构反馈
影响性分析说明:
CVE-2026-8924影响curl 7.46.0至8.20.0,master和6.0.0均使用curl 7.78.0,位于受影响范围;当curl访问带尾点的主机名且恶意HTTP服务器设置同样带尾点的Cookie Domain时,Cookie解析逻辑可能绕过Public Suffix List检查并设置覆盖公共后缀的超级Cookie,导致该Cookie随后被发送给不相关的第三方域名;两个分支已回移CVE-2026-8924.patch,在执行PSL检查前规范化并移除域名尾点,并由build.sh在构建时应用补丁完成修复。
漏洞评分(openGauss评分):
BaseScore: 9.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
受影响版本排查(受影响/不受影响):
1.master:受影响