Security Advisory

CVE-2026-6429

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 08:28:36
Last updated 2026-05-13 14:03:55
Assigner curl
CVSS score not scored
State PUBLISHED

Description

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.