Tools AI-Found Vulnerability Register aifv-0016
Register entry
curl out-of-bounds read in cookie path handling, found by Google Big Sleep
- CVE
- CVE-2025-9086
- Project
- curl
- Component
- cookie path
- Finder
- Google Big Sleep
- Autonomy
- agent finds and reproduces; a human expert reviews before reporting
- Evidence tier
- Credits array names the finder
- Assigner
- curl
- Bounty
- HackerOne (curl), report 3294999; amount unpublished
- Confidence
- CONFIRMED
What happened
An out-of-bounds read for the cookie path in curl up to 8.15.0, assigned by curl with Big Sleep as finder and Daniel Stenberg as remediation developer. The record carries no datePublic and no CVSS; its third reference is HackerOne report 3294999.
Credit as recorded: finder: "Google Big Sleep"; remediation developer: Daniel Stenberg. Date basis: datePublished.
Sources
- CVE record, cvelistV5 mirrorraw.githubusercontent.com/CVEProject/cvelistV5/main/cves/202…
On YFarmX
- Reference pageyfarmx.com/ai/security/big-sleep/
One record from the AI-Found Vulnerability Register, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 19 September 2026