When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.
https://hackerone.com/reports/3677759
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-29930