CVE-2026-8926
haxx curl: Insufficiently Protected Credentials
mediumEPSS 0.4%
Affected
- haxx/curl
between 8.11.1..8.21.0
Description
A flaw was found in curl. When curl is configured to use a .netrc file for credentials and a URL is provided with a username but no password, curl may incorrectly retrieve and use the password for a different user from the .netrc file for the same host. This could lead to unauthorized information disclosure, as curl might connect using unintended credentials.
Affected operating systems
linux
ubuntu / curltrusty
Metrics
Show all metrics
Severity
medium
61.51
no public PoC known
5.9
Published
2026-07-03 07:16 UTC
CWE-522
Weakness classes (CWE)
CWE-522Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-15 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
- Description: When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user. → When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
- CWE: CWE-522
- Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/8xxx/CVE-2026-8926.json">CVE-2026-8926</a>
- Reference: https://curl.se/docs/CVE-2026-8926.html
- CVE Modified2026-09-15 07:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- Reference: https://hackerone.com/reports/3735184
- Reference: https://hackerone.com/reports/3735184
- Reference Type: https://hackerone.com/reports/3735184 Types: Exploit, Issue Tracking, Third Party Advisory
- Initial Analysis2026-07-07 23:02 UTC· nvd@nist.gov
- CWE: CWE-522
- CPE Configuration: OR *cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* versions from (including) 8.11.1 up to (excluding) 8.21.0
- Reference Type: curl: https://curl.se/docs/CVE-2026-8926.html Types: Patch, Vendor Advisory
- Reference Type: curl: https://curl.se/docs/CVE-2026-8926.json Types: Vendor Advisory
- New CVE Received2026-07-03 07:16 UTC· 2499f714-1537-4658-8207-48ae4bb9eae9
- Affected: curl
- Description: When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
- Reference: https://curl.se/docs/CVE-2026-8926.html
- Reference: https://curl.se/docs/CVE-2026-8926.json