Related Vulnerabilities: CVE-2022-32205  

A vulnerability was found in curl. This issue occurs because a malicious server can serve excessive amounts of `Set-Cookie:` headers in an HTTP response to curl, which stores all of them. This flaw leads to a denial of service, either by mistake or by a malicious actor.

Description

A vulnerability was found in curl. This issue occurs because a malicious server can serve excessive amounts of `Set-Cookie:` headers in an HTTP response to curl, which stores all of them. This flaw leads to a denial of service, either by mistake or by a malicious actor.

Statement

This issue does not affect any Red Hat Enterprise Linux 6, 7, 8, and 9.

This issue does not affect any Red Hat Enterprise Linux 6, 7, 8, and 9.

Additional Information

  • Bugzilla 2099296: CVE-2022-32205 curl: Set-Cookie denial of service
  • CWE-770: Allocation of Resources Without Limits or Throttling
  • FAQ: Frequently asked questions about CVE-2022-32205