curl vulnerability

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

Published 13 May 2026Updated 15 Sep 20265 sources
CVSS 5.3 ✓ VERIFIED REFERENCE

Source timeline

CVE record published by NVDView source ↗