secure keyword for https://target
http://target (same
hostname, but using clear text HTTP) using the same cookie setpath=\"/\",).
Since this site is not secure, the cookie should just be ignored.The bug either causes a crash or it potentially makes the comparison come to the wrong conclusion and lets the clear-text site override the contents of the secure cookie, contrary to expectations and depending on the memory contents immediately following the single-byte allocation that holds the path.
The presumed and correct behavior would be to plainly ignore the second set of the cookie since it was already set as secure on a secure host so overriding it on an insecure host should not be okay.
{
"license": "CC-BY-4.0",
"sources": [
{
"published": "2025-09-12T06:15:44.100Z",
"id": "CVE-2025-9086",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-9086",
"imported": "2026-05-02T08:39:49.596Z",
"modified": "2026-01-20T14:58:01.347Z",
"database_specific": {
"status": "Analyzed"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-9086"
},
{
"published": "2025-09-12T06:30:26Z",
"url": "https://api.github.com/advisories/GHSA-v676-f8gm-92r9",
"imported": "2026-05-02T08:42:47.018Z",
"html_url": "https://github.com/advisories/GHSA-v676-f8gm-92r9",
"id": "GHSA-v676-f8gm-92r9",
"modified": "2026-01-20T15:31:21Z"
},
{
"published": "2025-09-12T05:10:03Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-29014",
"imported": "2026-05-02T08:41:27.977Z",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-29014",
"id": "EUVD-2025-29014",
"modified": "2026-01-08T09:51:46Z"
}
]
}