CVE-2026-6429 affecting package curl for versions less than 8.11.1-9
Details
When asked to both use a .netrc file for credentials and to follow HTTP
redirects, libcurl could leak the password used for the first host to the
followed-to host under certain circumstances.