FlawAtlas
Search the atlas
CVE-2026-6429 Moderate

netrc credential leak with reused proxy connection

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

Exploit probability 0.5%
Published May 13, 2026
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

167 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:10674-1
related SUSE-SU-2026:1717-1
related SUSE-SU-2026:1940-1
related SUSE-SU-2026:21452-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-6429

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

View original source

05 / REFERENCES

Further evidence