CVE-2026-6276
Using libcurl, when a custom `Host:` header is first set for an HTTP request
and a second request is subsequently done u
Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
HIGH · CVSS 7.5
EPSS 0.00013
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules7
YARA rules0