Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-6276

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

A flaw was found in libcurl. This vulnerability allows for information disclosure when a custom Host: header is used in an initial HTTP request, and a subsequent request reuses the same connection without specifying a new Host: header. This can lead to libcurl incorrectly sending cookies intended for the first host to the second host, resulting in a cookie leak. This issue is categorized as an Origin Validation Error (CWE-346). Exploitation typically requires specific debugging configurations.

Отчет

This Low severity flaw affects libcurl when a custom Host: header is initially set for an HTTP request, and a subsequent request uses the same easy handle without a custom Host: header. This can lead to the second request sending cookies intended for the first host. The curl command-line tool is not affected by this issue. Exploitation typically requires specific debugging configurations, reducing its overall impact.

Меры по смягчению последствий

To mitigate this issue, avoid using custom Host: headers with libcurl, especially when reusing the same easy handle for multiple requests. This vulnerability primarily arises from specific debugging configurations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationbuild-of-trustee/trustee-rhel9Fix deferred
Confidential Compute Attestationconfidential-compute-attestation-tech-preview/trustee-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-operator-bundleFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorFix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/eventrouter-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/fluentd-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2461203curl: libcurl: Information disclosure due to cookie leak when reusing connections with custom Host headers

EPSS

Процентиль: 22%
0.00295
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

CVSS3: 7.5
nvd
3 месяца назад

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

CVSS3: 7.5
msrc
3 месяца назад

stale custom cookie host causes cookie leak

CVSS3: 7.5
debian
3 месяца назад

Using libcurl, when a custom `Host:` header is first set for an HTTP r ...

CVSS3: 7.5
github
3 месяца назад

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

EPSS

Процентиль: 22%
0.00295
Низкий

3.7 Low

CVSS3