CVE-2026-8926
When asking curl to use a .netrc file to find credentials and at the same
time specifying a URL with a username(without a password), like
https://user@example.com/, curl could wrongly get and use the password for
another user set in the .netrc file for that host if such a one exists and
there is no match for the specified user.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://curl.se/docs/CVE-2026-8926.html, https://curl.se/docs/CVE-2026-8926.json, https://hackerone.com/reports/3735184, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8926.json, https://nvd.nist.gov/vuln/detail/CVE-2026-8926