CVE-2026-6429 affecting package cmake for versions less than 3.30.3-14
Details
When asked to both use a .netrc file for credentials and to follow HTTP
redirects, libcurl could leak the password used for the first host to the
followed-to host under certain circumstances.