Executive brief
A security flaw in the libcurl library, which is used by many applications to transfer data over the internet, could allow sensitive login credentials to be leaked. If an application is configured to use a .netrc file for passwords and follows a web redirect through a proxy, it may accidentally send the password for the first website to the second website. This could allow a malicious server to capture user credentials.
Technical details
A credential leak exists in libcurl (CWE-200) when it is configured to use a .netrc file for authentication and follow HTTP redirects. The vulnerability is triggered when both the original and redirect URLs use unencrypted HTTP, are accessed via the same HTTP proxy, and reuse the same connection. Under these conditions, libcurl may fail to clear the password used for the initial host before sending the request to the redirected host. This issue does not affect the curl command-line tool. A fix is available in version 8.20.0.
Affected products
- curl libcurl 7.14.0 to 8.19.0
Timeline
- 2026-04-16: other: Reported to the curl project
- 2026-04-29: patched: libcurl 8.20.0 released
- 2026-04-29: advisory: Project curl security advisory published
- 2026-05-13: disclosed: NVD publication date