YFarmX logoYFarmX

Tools AI-Found Vulnerability Register aifv-0016

Register entry

curl out-of-bounds read in cookie path handling, found by Google Big Sleep

CVE
CVE-2025-9086
Project
curl
Component
cookie path
Finder
Google Big Sleep
Autonomy
agent finds and reproduces; a human expert reviews before reporting
Evidence tier
Credits array names the finder
Assigner
curl
Bounty
HackerOne (curl), report 3294999; amount unpublished
Confidence
CONFIRMED

What happened

An out-of-bounds read for the cookie path in curl up to 8.15.0, assigned by curl with Big Sleep as finder and Daniel Stenberg as remediation developer. The record carries no datePublic and no CVSS; its third reference is HackerOne report 3294999.

Credit as recorded: finder: "Google Big Sleep"; remediation developer: Daniel Stenberg. Date basis: datePublished.

Sources

One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026