THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-6276 (HIGH 7.5) — Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first ho

[NVD] CVE-2026-6276 (HIGH 7.5) — Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first ho

lownvdPublished 2026-05-13

CVE-2026-6276 CVSS: 7.5 HIGH Published: 2026-05-13T13:01:56.800

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-6276