CVE-2026-11856
curl
Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
- CVSS
- 9.8
- EPSS
- 0.60% 45.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.03