CVE-2026-5773: wrong reuse of SMB connection; disable connection reuse for
SMB(S) so a subsequent transfer cannot wrongfully reuse a pooled connection
to a different share
CVE-2026-6276: clear stale custom-Host cookiehost between requests on the
same easy handle (cookie leak across origins)