curl Credential Inference via .netrc/Username Mismatch
CVE-2026-8926 Published on July 3, 2026
password leak with netrc and user in URL
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username (without a password), like
`https://user@example.com/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
Vulnerability Analysis
CVE-2026-8926 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-8926. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Products Associated with CVE-2026-8926
stack.watch emails you whenever new vulnerabilities are published in Canonical Ubuntu Linux or Haxx Curl. Just hit a watch button to start following.
Affected Versions
curl:- Version 8.11.1 and below 8.14.2 is affected.
- Version 8.15.0 and below 8.16.1 is affected.
- Version 8.17.0 and below 8.20.1 is affected.
- Version e9b9bbac22c26cf67316fa8e6c6b9e831af31949 and below 4ae1d7cc2643e4773a136395f12bc02fc6867854 is affected.
- Version 8.20.0 is affected.
- Version 8.19.0 is affected.
- Version 8.18.0 is affected.
- Version 8.17.0 is affected.
- Version 8.16.0 is affected.
- Version 8.15.0 is affected.
- Version 8.14.1 is affected.
- Version 8.14.0 is affected.
- Version 8.13.0 is affected.
- Version 8.12.1 is affected.
- Version 8.12.0 is affected.
- Version 8.11.1 is affected.