CVE-2026-8926
EUVD-2026-4150703.07.2026, 07:16
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| haxx | curl | 8.11.1 ≤ 𝑥 < 8.21.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| curl | curl | 8.11.1 ≤ 𝑥 < 8.14.2 | CNA |
| curl | curl | 8.15.0 ≤ 𝑥 < 8.16.1 | CNA |
| curl | curl | 8.17.0 ≤ 𝑥 < 8.20.1 | CNA |
| curl | curl | 8.20.0 | CNA |
| curl | curl | 8.19.0 | CNA |
| curl | curl | 8.18.0 | CNA |
| curl | curl | 8.17.0 | CNA |
| curl | curl | 8.16.0 | CNA |
| curl | curl | 8.15.0 | CNA |
| curl | curl | 8.14.1 | CNA |
| curl | curl | 8.14.0 | CNA |
| curl | curl | 8.13.0 | CNA |
| curl | curl | 8.12.1 | CNA |
| curl | curl | 8.12.0 | CNA |
| curl | curl | 8.11.1 | CNA |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| curl |
| ||||||||||||
| libcurl-devel |
| ||||||||||||
| libcurl4 |
| ||||||||||||
| libcurl4-32bit |
|
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| curl |
| ||
| curl-debuginfo |
| ||
| curl-debugsource |
| ||
| curl-minimal |
| ||
| curl-minimal-debuginfo |
| ||
| libcurl |
| ||
| libcurl-debuginfo |
| ||
| libcurl-devel |
| ||
| libcurl-minimal |
| ||
| libcurl-minimal-debuginfo |
|
Common Weakness Enumeration