CVE-2026-6429
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/05/2026
Last modified:
13/05/2026
Description
When asked to both use a `.netrc` file for credentials and to follow HTTP<br />
redirects, libcurl could leak the password used for the first host to the<br />
followed-to host under certain circumstances.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM



