Количество 9
Количество 9
CVE-2026-8926
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
CVE-2026-8926
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
CVE-2026-8926
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
CVE-2026-8926
password leak with netrc and user in URL
CVE-2026-8926
When asking curl to use a `.netrc` file to find credentials and at the ...
GHSA-vw2x-3w8j-rq82
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
openSUSE-SU-2026:21774-1
Security update for curl
SUSE-SU-2026:4047-1
Security update for curl
SUSE-SU-2026:3798-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-8926 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-8926 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. | CVSS3: 4.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-8926 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
CVE-2026-8926 password leak with netrc and user in URL | CVSS3: 5.9 | 0% Низкий | 2 месяца назад | |
CVE-2026-8926 When asking curl to use a `.netrc` file to find credentials and at the ... | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
GHSA-vw2x-3w8j-rq82 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. | CVSS3: 9.1 | 0% Низкий | 2 месяца назад | |
openSUSE-SU-2026:21774-1 Security update for curl | 9 дней назад | |||
SUSE-SU-2026:4047-1 Security update for curl | 9 дней назад | |||
SUSE-SU-2026:3798-1 Security update for curl | 22 дня назад |
Уязвимостей на страницу