๐Ÿ” CVE Alert

CVE-2026-6276

HIGH 7.5

stale custom cookie host causes cookie leak

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

CWE CWE-346
Vendor curl
Product curl
Published May 13, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for curl curl

Be the first to know when new high vulnerabilities affecting curl curl are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

curl / curl
7.71.0 < 8.14.2 8.15.0 < 8.16.1 8.17.0 < 8.20.0
curl / curl
e15e51384a423be31318b3c9c7d612a1aae661fd < 3a19987a87f393d9394fe5acc7643f6c263c92db
curl / curl
8.19.0 8.18.0 8.17.0 8.16.0 8.15.0 8.14.1 8.14.0 8.13.0 8.12.1 8.12.0 8.11.1 8.11.0 8.10.1 8.10.0 8.9.1 8.9.0 8.8.0 8.7.1 8.7.0 8.6.0 8.5.0 8.4.0 8.3.0 8.2.1 8.2.0 8.1.2 8.1.1 8.1.0 8.0.1 8.0.0 7.88.1 7.88.0 7.87.0 7.86.0 7.85.0 7.84.0 7.83.1 7.83.0 7.82.0 7.81.0 7.80.0 7.79.1 7.79.0 7.78.0 7.77.0 7.76.1 7.76.0 7.75.0 7.74.0 7.73.0 7.72.0 7.71.1 7.71.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
curl.se: https://curl.se/docs/CVE-2026-6276.json curl.se: https://curl.se/docs/CVE-2026-6276.html hackerone.com: https://hackerone.com/reports/3671818 openwall.com: http://www.openwall.com/lists/oss-security/2026/04/29/13

Credits

Muhamad Arga Reksapati Daniel Stenberg