{"id":"CVE-2026-63481","aliases":["GHSA-7w2g-9mf9-324m"],"url":"https://o3.security/vulnerability/CVE-2026-63481","summary":"Hurl: Cookies in Cookies section leak when redirecting to a different host","details":"Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth credentials when a redirect changes host, but it carries RequestSpec.cookies created from the dedicated [Cookies] section into the redirected request. An attacker-controlled redirect can therefore receive authentication or session cookies that should remain scoped to the original host. Cookies supplied through a raw Cookie header are stripped and are not affected by this specific path. This issue is reported as fixed in version 8.1.0.","published":"2026-08-20T16:28:24.282Z","modified":"2026-08-23T03:42:55.628086218Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"crates.io","name":"hurl","fixedVersion":null}],"fix":{"url":"https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e","label":"Orange-OpenSource/hurl@ed91c89"},"references":[{"type":"WEB","url":"https://github.com/Orange-OpenSource/hurl/releases/tag/8.0.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63481.json"},{"type":"ADVISORY","url":"https://github.com/Orange-OpenSource/hurl/security/advisories/GHSA-7w2g-9mf9-324m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63481"},{"type":"FIX","url":"https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e"},{"type":"FIX","url":"https://github.com/Orange-OpenSource/hurl/pull/5119"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-23T03:42:55.628086218Z"}}