Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8926

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 4.8

Описание

When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username(without a password), like https://user@example.com/, curl could wrongly get and use the password for another user set in the .netrc file for that host if such a one exists and there is no match for the specified user.

A flaw was found in curl. When curl is configured to use a .netrc file for credentials and a URL is provided with a username but no password, curl may incorrectly retrieve and use the password for a different user from the .netrc file for the same host. This could lead to unauthorized information disclosure, as curl might connect using unintended credentials.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Enterprise Linux 8curlNot affected
Red Hat Enterprise Linux 9curlNot affected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Fix deferred
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Fix deferred
Red Hat Hardened Imagescurl-main-8.21.0-0.1.hum1FixedRHSA-2026:2901724.06.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-289
https://bugzilla.redhat.com/show_bug.cgi?id=2496760curl: curl: Information disclosure via incorrect .netrc password lookup

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
2 месяца назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

CVSS3: 9.1
nvd
2 месяца назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

CVSS3: 5.9
msrc
2 месяца назад

password leak with netrc and user in URL

CVSS3: 9.1
debian
2 месяца назад

When asking curl to use a `.netrc` file to find credentials and at the ...

CVSS3: 9.1
github
2 месяца назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

4.8 Medium

CVSS3