CVE-2026-8926
published 2026-07-03CVE-2026-8926: When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like…
PriorityP354critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.61%
45.3th percentile
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://[email protected]/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.11.1 – 8.11.1 | — |
| curl | curl | 8.12.0 – 8.12.0 | — |
| curl | curl | 8.12.1 – 8.12.1 | — |
| curl | curl | 8.13.0 – 8.13.0 | — |
| curl | curl | 8.14.0 – 8.14.0 | — |
| curl | curl | 8.14.1 – 8.14.1 | — |
| curl | curl | 8.15.0 – 8.15.0 | — |
| curl | curl | 8.16.0 – 8.16.0 | — |
| curl | curl | 8.17.0 – 8.17.0 | — |
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| curl | curl | 8.20.0 – 8.20.0 | — |
| devspaces | code-rhel9 | — | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.11.1 < 8.21.0 | 8.21.0 |
| rhtpa | rhtpa-trustification-service-rhel9 | — | — |
| rust-lang | rust | — | — |
| ubuntu | curl | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
curl: curl: Information disclosure via incorrect .netrc password lookup
vendor_redhat·2026-07-03·CVSS 9.1
CVE-2026-8926 [CRITICAL] CWE-289 curl: curl: Information disclosure via incorrect .netrc password lookup
curl: curl: Information disclosure via incorrect .netrc password lookup
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://[email protected]/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
A flaw was found in curl. When curl is configured to use a .netrc file for credentials and a URL is provided with a username but no password, curl may incorrectly retrieve and use the password for a different user from the .netrc file for the same host. This could lead to unauthorized information disclosure, as curl might connect using unintended credentials.
Mitigation: Mitigation fo
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
GHSA
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://[email protected]/`, curl could wrongly get and use
ghsa_unreviewed·2026-07-03
CVE-2026-8926 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://[email protected]/`, curl could wrongly get and use
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://[email protected]/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8926 rpi-imager: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
bugzilla·2026-07-06·CVSS 9.1
CVE-2026-8926 [CRITICAL] CVE-2026-8926 rpi-imager: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
CVE-2026-8926 rpi-imager: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://[email protected]/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
Bugzilla
CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
bugzilla·2026-07-06·CVSS 9.1
CVE-2026-8926 [CRITICAL] CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://[email protected]/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
Bugzilla
CVE-2026-8926 mingw-curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
bugzilla·2026-07-06·CVSS 9.1
CVE-2026-8926 [CRITICAL] CVE-2026-8926 mingw-curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
CVE-2026-8926 mingw-curl: curl: Information disclosure via incorrect .netrc password lookup [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://[email protected]/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
Bugzilla
CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup
bugzilla·2026-07-03·CVSS 9.1
CVE-2026-8926 [CRITICAL] CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup
CVE-2026-8926 curl: curl: Information disclosure via incorrect .netrc password lookup
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://[email protected]/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
2026-07-03
Published