CVE-2026-11856
Successfully using libcurl to do a transfer to a specific HTTP origin
(hostA) with Digest authentication and then changing the origin to a
different one (hostB) for a second transfer, reusing the same handle, makes
libcurl wrongly pass on the Authorization: header field meant for hostA,
to hostB.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://curl.se/docs/CVE-2026-11856.html, https://curl.se/docs/CVE-2026-11856.json, https://hackerone.com/reports/3793260, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11856.json, https://nvd.nist.gov/vuln/detail/CVE-2026-11856