Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-6429

Опубликовано: 13 мая 2026
Источник: debian

Описание

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.20.0~rc3-1package
curlfixed8.14.1-2+deb13u4trixiepackage
curlno-dsabookwormpackage
curlpostponedbullseyepackage

Примечания

  • https://curl.se/docs/CVE-2026-6429.html

  • Introduced by: https://github.com/curl/curl/commit/01165e08e0d131b399fba2190f17af67e66f0888 (curl-7_14_0)

  • Fixed by: https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306 (rc-8_20_0-3)

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

CVSS3: 6.5
redhat
3 месяца назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

CVSS3: 5.3
nvd
3 месяца назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

CVSS3: 5.3
msrc
3 месяца назад

netrc credential leak with reused proxy connection

CVSS3: 5.3
github
3 месяца назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.