Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-8926

Опубликовано: 03 июл. 2026
Источник: debian

Описание

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.21.0~rc2-1package
curlno-dsatrixiepackage
curlnot-affectedbookwormpackage
curlnot-affectedbullseyepackage

Примечания

  • https://curl.se/docs/CVE-2026-8926.html

  • Introduced with: https://github.com/curl/curl/commit/e9b9bbac22c26cf67316fa8e6c6b9e831af31949 (curl-8_11_1)

  • Fixed by: https://github.com/curl/curl/commit/4ae1d7cc2643e4773a136395f12bc02fc6867854 (rc-8_21_0-1, curl-8_21_0)

Связанные уязвимости

CVSS3: 9.1
ubuntu
28 дней назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

CVSS3: 4.8
redhat
28 дней назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

CVSS3: 9.1
nvd
28 дней назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

CVSS3: 5.9
msrc
24 дня назад

password leak with netrc and user in URL

CVSS3: 9.1
github
28 дней назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.