Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-8926

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username(without a password), like https://user@example.com/, curl could wrongly get and use the password for another user set in the .netrc file for that host if such a one exists and there is no match for the specified user.

A flaw was found in curl. When curl is configured to use a .netrc file for credentials and a URL is provided with a username but no password, curl may incorrectly retrieve and use the password for a different user from the .netrc file for the same host. This could lead to unauthorized information disclosure, as curl might connect using unintended credentials.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10curlAffected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Enterprise Linux 8curlNot affected
Red Hat Enterprise Linux 9curlNot affected
Red Hat OpenShift Container Platform 4rhcosFix deferred
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Fix deferred
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Fix deferred
Red Hat Hardened Imagescurl-main-8.21.0-0.1.hum1FixedRHSA-2026:2901724.06.2026
Red Hat Hardened Imagesrust-main-1.96.1-1.hum1FixedRHSA-2026:3497502.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-289
https://bugzilla.redhat.com/show_bug.cgi?id=2496760curl: curl: Information disclosure via incorrect .netrc password lookup

EPSS

Процентиль: 46%
0.0061
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
28 дней назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

CVSS3: 9.1
nvd
28 дней назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

CVSS3: 5.9
msrc
24 дня назад

password leak with netrc and user in URL

CVSS3: 9.1
debian
28 дней назад

When asking curl to use a `.netrc` file to find credentials and at the ...

CVSS3: 9.1
github
28 дней назад

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

EPSS

Процентиль: 46%
0.0061
Низкий

4.8 Medium

CVSS3

Уязвимость CVE-2026-8926