Junglewise Threat Intelligence

CVE-2026-6276: Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy

CVE-2026-6276 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: Curl Libcurl, Haxx Curl. Vendors: Haxx.

Executive brief

A vulnerability in the libcurl library, which is widely used by applications to transfer data over the internet, could lead to the accidental disclosure of sensitive information. When an application makes multiple requests using the same connection handle, it may mistakenly send security cookies intended for one website to a different, subsequent website. This could allow an attacker to intercept session tokens or other private user data if they control the second destination.

Technical details

An origin validation error (CWE-346) exists in libcurl when an 'easy handle' is reused for subsequent HTTP requests. If a developer sets a custom 'Host:' header for an initial request and then performs a second request using the same handle without that custom header, libcurl may retain stale host information. This causes the library to attach cookies belonging to the first host to the second request, even if the second request is destined for a different domain. The impact is primarily limited to clear-text HTTP transfers, as HTTPS transfers typically require matching SNI (Server Name Indication) which mitigates the risk of cross-domain leakage. The issue is fixed in version 8.20.0.

Affected products

  • curl libcurl 7.71.0 to 8.19.0

Timeline

  • 2026-04-14: disclosed: Reported to the curl project via HackerOne.
  • 2026-04-29: patched: libcurl 8.20.0 released.
  • 2026-04-29: advisory: Project advisory published.
  • 2026-05-13: other: NVD publication date.

References

Related threats