High severity7.5NVD Advisory· Published May 13, 2026· Updated May 14, 2026
CVE-2026-6276
CVE-2026-6276
Description
Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom Host: header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- curl.se/docs/CVE-2026-6276.htmlnvdPatchVendor Advisory
- hackerone.com/reports/3671818nvdExploitIssue TrackingThird Party Advisory
- www.openwall.com/lists/oss-security/2026/04/29/13nvdMailing ListThird Party Advisory
- curl.se/docs/CVE-2026-6276.jsonnvdProduct
News mentions
0No linked articles in our index yet.