CVE-2026-11856Patch(haxx / curl)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haxx curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-294

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-08); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-08: 1Mentions · 2026-08-01: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-08-01: 1Technical Details · 2026-07-08: 107-0808-01
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-081
Patch1
2026-08-011
Disclosure1
Full discourse2 posts
  • SecAlerts@SecAlertsCo
    Patch

    🔐 curl CVE-2026-11856: critical Digest auth state leak. Credentials from one HTTP origin silently reused against a different host on the next transfer. CVSS 9.8, patch available now. https://secalerts.co/vulnerability/CVE-2026-11856?utm_campaign=x https://t.co/xxdMNeBQAq

    Post summary

    The post discloses a critical Digest authentication state leak (CVE‑2026‑11856) and informs readers that a vendor patch is now available.

    01000159
    852 followersView on X
  • guriguri@guriguri_dW
    Disclosure

    #IBMAIX ■ Security Bulletin: Multiple vulnerabilities impact AIX due to CURL libcurl (CVE-2026-10536, CVE-2026-11856, CVE-2026-8286, CVE-2026-8458, CVE-2026-8924, CVE-2026-8927, CVE-2026-8932, CVE-2026-9547). https://www.ibm.com/support/pages/node/7281743 沢山あります! 😱

    Post summary

    IBM released a security bulletin announcing eight AIX vulnerabilities linked to libcurl and provided a link to a vendor advisory.

    0000051
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more