CVE-2026-6276
HIGHcurl 8.7.0-8.19.0 - Sensitive Cookie Leak via Stale Host Header
Title source: llmDescription
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
References (4)
Core 4
Core References
Scores
CVSS v3
7.5
EPSS
0.0001
EPSS Percentile
2.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-319
Status
published
Products (50)
curl/curl
7.71.0
curl/curl
7.71.1
curl/curl
7.72.0
curl/curl
7.73.0
curl/curl
7.74.0
curl/curl
7.75.0
curl/curl
7.76.0
curl/curl
7.76.1
curl/curl
7.77.0
curl/curl
7.78.0
... and 40 more
Published
May 13, 2026
Tracked Since
May 13, 2026