Back

LOW

netrc and default credential leak

Published Feb 5, 2025

Description

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner curl
Published Feb 5, 2025
Updated Mar 7, 2025
Reserved Dec 31, 2024

CISA Vulnrichment

Updated Feb 5, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner curl
Published Feb 5, 2025
Updated Mar 7, 2025

GitHub

No data