Executive brief
A vulnerability in the libcurl library, which is widely used by applications to transfer data over the internet, could lead to the accidental disclosure of sensitive information. When an application makes multiple requests using the same connection handle, it may mistakenly send security cookies intended for one website to a different, subsequent website. This could allow an attacker to intercept session tokens or other private user data if they control the second destination.
Technical details
An origin validation error (CWE-346) exists in libcurl when an 'easy handle' is reused for subsequent HTTP requests. If a developer sets a custom 'Host:' header for an initial request and then performs a second request using the same handle without that custom header, libcurl may retain stale host information. This causes the library to attach cookies belonging to the first host to the second request, even if the second request is destined for a different domain. The impact is primarily limited to clear-text HTTP transfers, as HTTPS transfers typically require matching SNI (Server Name Indication) which mitigates the risk of cross-domain leakage. The issue is fixed in version 8.20.0.
Affected products
- curl libcurl 7.71.0 to 8.19.0
Timeline
- 2026-04-14: disclosed: Reported to the curl project via HackerOne.
- 2026-04-29: patched: libcurl 8.20.0 released.
- 2026-04-29: advisory: Project advisory published.
- 2026-05-13: other: NVD publication date.