Количество 9
Количество 9
CVE-2026-6276
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
CVE-2026-6276
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
CVE-2026-6276
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
CVE-2026-6276
stale custom cookie host causes cookie leak
CVE-2026-6276
Using libcurl, when a custom `Host:` header is first set for an HTTP r ...
GHSA-2jc6-hc33-hv48
Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.
openSUSE-SU-2026:20973-1
Security update for curl
SUSE-SU-2026:1940-1
Security update for curl
SUSE-SU-2026:1717-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6276 Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6276 Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
CVE-2026-6276 Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6276 stale custom cookie host causes cookie leak | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-6276 Using libcurl, when a custom `Host:` header is first set for an HTTP r ... | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-2jc6-hc33-hv48 Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:20973-1 Security update for curl | около 2 месяцев назад | |||
SUSE-SU-2026:1940-1 Security update for curl | 3 месяца назад | |||
SUSE-SU-2026:1717-1 Security update for curl | 3 месяца назад |
Уязвимостей на страницу