CVE-2026-8926

haxx curl: Insufficiently Protected Credentials

mediumEPSS 0.4%

Affected

  • haxx/curl between 8.11.1..8.21.0

Description

A flaw was found in curl. When curl is configured to use a .netrc file for credentials and a URL is provided with a username but no password, curl may incorrectly retrieve and use the password for a different user from the .netrc file for the same host. This could lead to unauthorized information disclosure, as curl might connect using unintended credentials.

Affected operating systems

  • linux

    ubuntu / curltrusty

Metrics

5.9
Source: nvd-v3
36.6 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
Show all metrics
Severity
medium
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-03 07:16 UTC
CWE-522

Weakness classes (CWE)

  • CWE-522Class

    Insufficiently Protected Credentials

    The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-15 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Description: When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. → When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
    • CWE: CWE-522
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/8xxx/CVE-2026-8926.json">CVE-2026-8926</a>
    • Reference: https://curl.se/docs/CVE-2026-8926.html
  2. CVE Modified2026-09-15 07:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • Reference: https://hackerone.com/reports/3735184
    • Reference: https://hackerone.com/reports/3735184
    • Reference Type: https://hackerone.com/reports/3735184 Types: Exploit, Issue Tracking, Third Party Advisory
  3. Initial Analysis2026-07-07 23:02 UTC· nvd@nist.gov
    • CWE: CWE-522
    • CPE Configuration: OR *cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* versions from (including) 8.11.1 up to (excluding) 8.21.0
    • Reference Type: curl: https://curl.se/docs/CVE-2026-8926.html Types: Patch, Vendor Advisory
    • Reference Type: curl: https://curl.se/docs/CVE-2026-8926.json Types: Vendor Advisory
  4. New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
    • Affected: curl
    • Description: When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
    • Reference: https://curl.se/docs/CVE-2026-8926.html
    • Reference: https://curl.se/docs/CVE-2026-8926.json

Linked advisories