Logo
vulnerabilityCVE-2026-6276
Name
CVE-2026-6276
Source
NVD ( link)Debian ( link)
Description
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
curl
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
8.20.0
Not Affected
buildroot
master
8.21.0
Not Affected
openwrt
openwrt-25.12
8.19.0-r2
Exploitable
openwrt
openwrt-25.12
8.14.1-r1
Exploitable
yocto
kirkstone
7.82.0
Exploitable
yocto
master
8.20.0
Not Affected
yocto
scarthgap
8.7.1
Exploitable