When asked to both use a `.netrc` file for credentials and to follow HTTP
redirects, libcurl could leak the password used for the first host to the
followed-to host under certain circumstances.
References
| Link | Resource |
|---|---|
| https://curl.se/docs/CVE-2026-6429.html | Patch Vendor Advisory |
| https://curl.se/docs/CVE-2026-6429.json | Product |
| https://hackerone.com/reports/3677759 | Exploit Issue Tracking Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-05-13 13:01
Updated : 2026-09-15 07:16
NVD link : CVE-2026-6429
Mitre link : CVE-2026-6429
CVE.ORG link : CVE-2026-6429
JSON object : View
Products Affected
haxx
- curl
CWE
