THREAT OPS › Threat News › [NVD] CVE-2026-6276 (HIGH 7.5) — Using libcurl, when a custom `Host:` header is first set for an HTTP request
and a second request is subsequently done using the same *easy handle* but
without the custom `Host:` header set, the second request would use stale
information and pass on cookies meant for the first ho
[NVD] CVE-2026-6276 (HIGH 7.5) — Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first ho
CVE-2026-6276 CVSS: 7.5 HIGH Published: 2026-05-13T13:01:56.800
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
Indicators of compromise
- CVE-2026-6276cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-6276