CVE-2026-6276
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.29%
- CWE
- CWE-346
- Published
- 2026-05-13
- Last modified
- 2026-09-17
Affected products
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
- curl curl
Weakness type
Related vulnerabilities
- CVE-2025-34291 — Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
- CVE-2026-54069 — SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
- CVE-2025-9265 — API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
- CVE-2025-69258 — A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta
- CVE-2026-22794 — Account Takeover Vulnerability in Appsmith
- CVE-2025-59159 — SillyTavern Web Interface Vulnerable to DNS Rebinding
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2024-14006 — Nagios XI < 2024R1.2.2 Host Header Injection