Feed/CVE-2026-8926
CVE-2026-8926CRITICALCVSS 9.1

CVE-2026-8926

Published Jul 3, 2026·Updated Jul 7, 2026

NVD Description

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free