Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6429

Опубликовано: 13 мая 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

When asked to both use a .netrc file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Версия от 7.14.0 (включая) до 8.20.0 (исключая)

EPSS

Процентиль: 41%
0.00519
Низкий

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

CVSS3: 6.5
redhat
3 месяца назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

CVSS3: 5.3
msrc
3 месяца назад

netrc credential leak with reused proxy connection

CVSS3: 5.3
debian
3 месяца назад

When asked to both use a `.netrc` file for credentials and to follow H ...

CVSS3: 5.3
github
3 месяца назад

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

EPSS

Процентиль: 41%
0.00519
Низкий

5.3 Medium

CVSS3

Дефекты

NVD-CWE-noinfo