CVE-2026-6276
ADVISORY - nistSummary
Using libcurl, when a custom Host: header is first set for an HTTP request
and a second request is subsequently done using the same easy handle but
without the custom Host: header set, the second request would use stale
information and pass on cookies meant for the first host in the second
request. Leak them.
EPSS Score: 0.00013 (0.021)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Cleartext Transmission of Sensitive Information
ADVISORY - redhat
Origin Validation Error
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in