{"id":"JLSEC-2026-1207","summary":"Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request...","details":"Using libcurl, when a custom `Host:` header is first set for an HTTP request\nand a second request is subsequently done using the same *easy handle* but\nwithout the custom `Host:` header set, the second request would use stale\ninformation and pass on cookies meant for the first host in the second\nrequest. Leak them.","modified":"2026-08-07T20:29:10.235969879Z","published":"2026-08-07T20:11:58.984Z","upstream":["CVE-2026-6276","EUVD-2026-29928","GHSA-2jc6-hc33-hv48"],"database_specific":{"license":"CC-BY-4.0","sources":[{"database_specific":{"status":"Analyzed"},"id":"CVE-2026-6276","imported":"2026-08-07T19:54:38.653Z","modified":"2026-06-17T11:00:35.067Z","published":"2026-05-13T13:01:56.800Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-6276","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276"},{"published":"2026-05-13T18:30:52Z","url":"https://api.github.com/advisories/GHSA-2jc6-hc33-hv48","html_url":"https://github.com/advisories/GHSA-2jc6-hc33-hv48","id":"GHSA-2jc6-hc33-hv48","imported":"2026-08-07T19:56:10.488Z","modified":"2026-05-14T15:31:56Z"},{"id":"EUVD-2026-29928","imported":"2026-08-07T19:55:26.659Z","modified":"2026-05-13T17:26:06Z","published":"2026-05-13T08:28:19Z","url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-29928","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29928"}]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/04/29/13"},{"type":"WEB","url":"https://curl.se/docs/CVE-2026-6276.html"},{"type":"WEB","url":"https://curl.se/docs/CVE-2026-6276.json"},{"type":"WEB","url":"https://github.com/advisories/GHSA-2jc6-hc33-hv48"},{"type":"WEB","url":"https://hackerone.com/reports/3671818"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6276"}],"affected":[{"package":{"name":"CURL_jll","ecosystem":"Julia","purl":"pkg:julia/CURL_jll?uuid=b21e61f3-bafc-59ac-ab14-4c5c62d6588d"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.20.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1207.json"}},{"package":{"name":"LibCURL_jll","ecosystem":"Julia","purl":"pkg:julia/LibCURL_jll?uuid=deac9b47-8bc7-5906-a0fe-35ac56dc84c0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.71.1+0"},{"fixed":"8.20.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1207.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}