When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApple macOS
OSApple< 13.0Debian
OSDebian11.0Fedora Project Fedora
OSFedoraproject35Haxx Curl
APPHaxx7.69.0 – 7.84.0 (excl.)Netapp Bootstrap Os
OSNetappall versionsNetapp Clustered Data Ontap
APPNetappall versionsNetapp Element Software
APPNetappall versionsNetapp H300s
HWNetappall versionsNetapp H300s Firmware
OSNetappall versionsNetapp H410s
HWNetappall versionsNetapp H410s Firmware
OSNetappall versionsNetapp H500s
HWNetappall versionsNetapp H500s Firmware
OSNetappall versionsNetapp H700s
HWNetappall versionsNetapp H700s Firmware
OSNetappall versionsNetapp Hci Compute Node
HWNetappall versionsNetapp Hci Management Node
APPNetappall versionsNetapp Solidfire
APPNetappall versionsSplunk Universal Forwarder
APPSplunk9.1.08.2.0 – 8.2.12 (excl.)9.0.0 – 9.0.6 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product
Pominięcie uwierzytelniania w Screen Sharing na macOS
CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product
Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)