CVE-2026-11856
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.69%
- CWE
- CWE-294
- Published
- 2026-07-03
- Last modified
- 2026-09-17
Affected products
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
Weakness type
Related vulnerabilities
- CVE-2026-65905 — Apache Tomcat: Limited replay attack possible with DIGEST authentication
- CVE-2024-38438 — D-Link - CWE-294: Authentication Bypass by Capture-replay
- CVE-2025-6030 — Autoeastern Smart Keyless Entry System Replay Attack
- CVE-2025-6029 — KIA-branded Aftermarket Generic Smart Keyless Entry System Replay Attack
- CVE-2023-0014 — Capture-replay vulnerability in SAP NetWeaver AS for ABAP and ABAP Platform
- CVE-2025-36593 — Dell OpenManage Network Integration, versions prior to 3.8, contains an Authentication Bypass by Capture-replay vulnerab
- CVE-2024-43099 — AutomationDirect DirectLogic H2-DM1E Authentication Bypass by Capture-replay
- CVE-2024-12839 — Changing Information Technology CGFIDO - Authentication Bypass