CVE-2022-32205
Splunk Forwarder vulnerability analysis and mitigation

Overview

CVE-2022-32205 is a vulnerability in curl versions 7.71.0 to 7.83.1 where a malicious server can serve excessive amounts of Set-Cookie headers in an HTTP response. The vulnerability was discovered on May 13, 2022 and fixed in curl 7.84.0 released on June 27, 2022 (Curl Advisory).

Technical details

The vulnerability occurs when curl stores all Set-Cookie headers received from a server response. A sufficiently large amount of big cookies can make subsequent HTTP requests to matching servers create requests larger than curl's internal threshold of 1,048,576 bytes, causing curl to return an error. Due to cookie matching rules, a server on foo.example.com can set cookies that would also match for bar.example.com, enabling a 'sister server' to cause denial of service for sibling sites on the same second level domain (Curl Advisory).

Impact

The vulnerability can lead to a denial of service state that might remain active as long as the cookies are kept, match and have not expired. This affects subsequent requests to the same or other servers where the cookies match (Curl Advisory, NVD).

Mitigation and workarounds

The vulnerability was fixed in curl 7.84.0 with several new limits: maximum 150 cookies per request, 8K cap on outgoing Cookie header length, and maximum 50 accepted Set-Cookie header fields. Users should upgrade to curl version 7.84.0 or later, apply available patches, or avoid using cookies as a workaround (Curl Advisory).

Additional resources


SourceThis report was generated using AI

Related Splunk Forwarder vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-20298HIGH8
  • Splunk ForwarderSplunk Forwarder
  • cpe:2.3:a:splunk:universal_forwarder
NoYesJun 02, 2025
CVE-2023-27537MEDIUM5.9
  • MySQLMySQL
  • mysql
NoYesMar 30, 2023
CVE-2023-27536MEDIUM5.9
  • MySQLMySQL
  • libcurl-devel-32bit
NoYesMar 30, 2023
CVE-2023-27535MEDIUM5.9
  • MySQLMySQL
  • cpe:2.3:a:haxx:libcurl
NoYesMar 30, 2023
CVE-2023-27538MEDIUM5.5
  • MySQLMySQL
  • curl-devel
NoYesMar 30, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management