PT-2026-35896 · Curl+2 · Libcurl+2

Daniel Stenberg

·

Published

2026-04-29

·

Updated

2026-06-05

·

CVE-2026-6429

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions libcurl (affected versions not specified)
Description When configured to use a .netrc file for credentials and to follow HTTP redirects, libcurl may leak the password used for the initial host to the subsequent host during the redirect process under certain circumstances.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6429
ECHO-2EC8-1A62-F90D
OESA-2026-2477
OPENSUSE-SU-2026:10674-1
RHSA-2026:12916
USN-8227-1

Affected Products

Linuxmint
Ubuntu
Libcurl