CVE-2026-8926Disclosure(haxx / curl)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-522

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-09: 1Technical Details · 2026-07-09: 107-09
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - curl .netrc credential confusion leaks wrong user password (CVE-2026-8926) This vulnerability affects curl’s .netrc credential lookup logic when authenticating to a host and the URL supplies a username but no password. The root cause is improper credential selection / authentication context mix-up, where curl can fall back to a different user’s password from the same host’s .netrc entries. An attacker can exploit this by getting a victim to request a crafted URL like https://user@example.com/ (or by controlling/redirecting the target host) in an environment where curl is configured to use .netrc and multiple users exist for that host. Impact includes unintended credential disclosure/use (auth to the wrong account), potential account compromise, and follow-on data access depending on what that misapplied credential can reach. 👉 Affected: curl (when using .netrc; versions not yet specified) | Upgrade to No fix yet - treat as suspicious

    Post summary

    The post announces a new CVE affecting curl’s .netrc handling, outlining the vulnerability’s mechanics and potential impact, but no exploitation evidence or fixes are available.

    0000094
    246 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more