Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-8926: curl can retrieve wrong password from .netrc
CVE-2026-8926 · published 3 months ago
Summary
The curl command-line tool may read a password from a .netrc file that belongs to a different user when the URL includes a username but no password. This can cause unintended credentials to be sent to a web server, potentially granting access to the wrong account. Update curl to the latest version or avoid mixing .netrc files with URLs that contain a username without a password.
What to do
- Update canonical curl to version 8.14.1-2ubuntu1.4.
- Update canonical curl to version 8.18.0-1ubuntu2.2.
- Update bellsoft curl to version 8.21.0-r0.
- Update debian curl to version 8.21.0~rc2-1.
- Update alpine curl to version 8.19.0-r00074.
- Update alpine rootio-curl to version 8.19.0-r00074.
- Update alpine curl to version 8.14.1-r20072.
- Update alpine rootio-curl to version 8.14.1-r20072.
- Update alpine curl to version 8.14.1-r20073.
- Update alpine rootio-curl to version 8.14.1-r20073.
- Update alpine curl to version 8.14.1-r20074.
- Update alpine rootio-curl to version 8.14.1-r20074.
- Update alpine curl to version 8.14.1-r20078.
- Update alpine rootio-curl to version 8.14.1-r20078.
- Update alpine curl to version 8.14.1-r20071.
- Update alpine rootio-curl to version 8.14.1-r20071.
- Update alpine curl to version 8.19.0-r00075.
- Update alpine rootio-curl to version 8.19.0-r00075.
- Update alpine curl to version 8.19.0-r00076.
- Update alpine rootio-curl to version 8.19.0-r00076.
- Update debian rootio-curl to version 8.14.1-2+deb13u4.aikido.14.
- Update debian curl to version 8.14.1-2+deb13u4.aikido.14.
- Update curl to version 8.14.1-r20079.
- Update rootio-curl to version 8.14.1-r20079.
- Update curl to version 8.14.1-2+deb13u5.aikido.18.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.18.
- Update curl to version 8.14.1-2+deb13u5.aikido.19.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
- Update curl to version 8.22.0-r0.
- Update curl to version 8.21.0-r0.
- Update curl to version 8.14.1-r30075.
- Update rootio-curl to version 8.14.1-r30075.
- Update curl to version 8.14.1-r200710.
- Update rootio-curl to version 8.14.1-r200710.
- Update curl to version 8.14.1-r30076.
- Update rootio-curl to version 8.14.1-r30076.
- Update curl to version 8.14.1-r20074.
- Update rootio-curl to version 8.14.1-r20074.
- Update curl to version 8.14.1-r200711.
- Update rootio-curl to version 8.14.1-r200711.
- Update curl to version 8.14.1-r30077.
- Update rootio-curl to version 8.14.1-r30077.
- Update curl to version 8.14.1-r20075.
- Update rootio-curl to version 8.14.1-r20075.
- Update curl to version 8.14.1-2+deb13u5.aikido.20.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
- Update haxx curl to version 8.21.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:25.10 | canonical | curl |
< 8.14.1-2ubuntu1.4 Fix: upgrade to 8.14.1-2ubuntu1.4
|
| Ubuntu:26.04:LTS | canonical | curl |
< 8.18.0-1ubuntu2.2 Fix: upgrade to 8.18.0-1ubuntu2.2
|
| – | curl | curl |
<= 8.20.0 < 8.14.2 < 4ae1d7cc2643e4773a136395f12bc02fc6867854 8.20.0 |
| Alpaquita:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.21.0-r0 Fix: upgrade to 8.21.0-r0
|
| Debian:13 | debian | curl | All versions |
| Debian:14 | debian | curl |
< 8.21.0~rc2-1 Fix: upgrade to 8.21.0~rc2-1
|
| Root:Alpine:3.23 | alpine | curl |
< 8.19.0-r00074 < 8.19.0-r00075 < 8.19.0-r00076 Fix: upgrade to 8.19.0-r00074
|
| Root:Alpine:3.23 | alpine | rootio-curl |
< 8.19.0-r00074 < 8.19.0-r00075 < 8.19.0-r00076 Fix: upgrade to 8.19.0-r00074
|
| Root:Alpine:3.21 | alpine | curl |
< 8.14.1-r20072 < 8.14.1-r20073 Fix: upgrade to 8.14.1-r20072
|
| Root:Alpine:3.21 | alpine | rootio-curl |
< 8.14.1-r20072 < 8.14.1-r20073 Fix: upgrade to 8.14.1-r20072
|
| Root:Alpine:3.22 | alpine | curl |
< 8.14.1-r20073 < 8.14.1-r20074 < 8.14.1-r20071 Fix: upgrade to 8.14.1-r20073
|
| Root:Alpine:3.22 | alpine | rootio-curl |
< 8.14.1-r20073 < 8.14.1-r20074 < 8.14.1-r20071 Fix: upgrade to 8.14.1-r20073
|
| BellSoft Hardened Containers:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.21.0-r0 Fix: upgrade to 8.21.0-r0
|
| Root:Alpine:3.20 | alpine | curl |
< 8.14.1-r20078 Fix: upgrade to 8.14.1-r20078
|
| Root:Alpine:3.20 | alpine | rootio-curl |
< 8.14.1-r20078 Fix: upgrade to 8.14.1-r20078
|
| Root:Debian:13 | debian | rootio-curl |
< 8.14.1-2+deb13u4.aikido.14 Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
|
| Root:Debian:13 | debian | curl |
< 8.14.1-2+deb13u4.aikido.14 Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
|
| Root:Alpine:3.20 | – | curl |
< 8.14.1-r20079 < 8.14.1-r200710 < 8.14.1-r200711 Fix: upgrade to 8.14.1-r20079
|
| Root:Alpine:3.20 | – | rootio-curl |
< 8.14.1-r20079 < 8.14.1-r200710 < 8.14.1-r200711 Fix: upgrade to 8.14.1-r20079
|
| Root:Debian:13 | – | curl |
< 8.14.1-2+deb13u5.aikido.18 < 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
|
| Root:Debian:13 | – | rootio-curl |
< 8.14.1-2+deb13u5.aikido.18 < 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
|
| – | haxx | curl |
>= 8.11.1, < 8.21.0 cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
| Alpine:v3.23 | – | curl |
>= 8.11.1, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Alpine:v3.24 | – | curl |
>= 8.11.1, < 8.21.0-r0 Fix: upgrade to 8.21.0-r0
|
| Root:Alpine:3.22 | – | curl |
< 8.14.1-r30075 < 8.14.1-r30076 < 8.14.1-r30077 Fix: upgrade to 8.14.1-r30075
|
| Root:Alpine:3.22 | – | rootio-curl |
< 8.14.1-r30075 < 8.14.1-r30076 < 8.14.1-r30077 Fix: upgrade to 8.14.1-r30075
|
| Root:Alpine:3.21 | – | curl |
< 8.14.1-r20074 < 8.14.1-r20075 Fix: upgrade to 8.14.1-r20074
|
| Root:Alpine:3.21 | – | rootio-curl |
< 8.14.1-r20074 < 8.14.1-r20075 Fix: upgrade to 8.14.1-r20074
|
Original advisory text
CVE-2026-8926 in curl - Patched by Root
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
References
- https://ubuntu.com/security/CVE-2026-8926 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8487-1 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-8926 Third Party Advisory
- https://curl.se/L7HzKXisfJ/CVE-2026-8926.md Third Party Advisory
- https://docs.bell-sw.com/security/cves/CVE-2026-8926 Vendor Advisory
- https://curl.se/docs/CVE-2026-8926.json URL
- https://github.com/curl/curl.git Product
- https://security-tracker.debian.org/tracker/CVE-2026-8926 Vendor Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-8926 Vendor Advisory
- https://curl.se/docs/CVE-2026-8926.html URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8926.j... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-8926 Vendor Advisory
- https://hackerone.com/reports/3735184 URL
Severity
9.1
Critical
Exploitation
EPSS <1%
Type
CWE-522Insufficiently Protected Credentials
Timeline
Published24 Jun 2026
Updated27 Sep 2026
First seen24 Jun 2026
Sources
UBUNTU-CVE-2026-8926 · OSV
CURL-CVE-2026-8926 · OSV
CVE-2026-8926 · NVD
CVE-2026-8926 · MITRE
BELL-CVE-2026-8926 · OSV
DEBIAN-CVE-2026-8926 · OSV
CVE-2026-8926 · OSV
ALPINE-CVE-2026-8926 · OSV
Track software like this
Free during beta