https://seclists.org/oss-sec/2026/q2/268: [ADVISORY] curl: CVE-2026-6429: netrc cdential leak with used proxy connection
Published Apr 29, 2026
·Updated
Affected Software
1 affected component
curl libcurl>=7.14.0<=8.19.0
Frequently Asked Questions
1
What is the severity of CVE-2026-6429?
CVE-2026-6429 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2026-6429?
To fix CVE-2026-6429, update your curl or libcurl to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-6429?
CVE-2026-6429 is a netrc credential leak vulnerability that can occur with reused proxy connections.
4
Which versions of curl are affected by CVE-2026-6429?
CVE-2026-6429 affects specific versions of curl that handle .netrc files without proper protection for proxy connections.
5
Can CVE-2026-6429 lead to credential theft?
Yes, CVE-2026-6429 can potentially lead to credential theft due to improper handling of .netrc files.