Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-8926: curl can retrieve wrong password from .netrc

CVE-2026-8926 · published 3 months ago
Summary

The curl command-line tool may read a password from a .netrc file that belongs to a different user when the URL includes a username but no password. This can cause unintended credentials to be sent to a web server, potentially granting access to the wrong account. Update curl to the latest version or avoid mixing .netrc files with URLs that contain a username without a password.

What to do
  • Update canonical curl to version 8.14.1-2ubuntu1.4.
  • Update canonical curl to version 8.18.0-1ubuntu2.2.
  • Update bellsoft curl to version 8.21.0-r0.
  • Update debian curl to version 8.21.0~rc2-1.
  • Update alpine curl to version 8.19.0-r00074.
  • Update alpine rootio-curl to version 8.19.0-r00074.
  • Update alpine curl to version 8.14.1-r20072.
  • Update alpine rootio-curl to version 8.14.1-r20072.
  • Update alpine curl to version 8.14.1-r20073.
  • Update alpine rootio-curl to version 8.14.1-r20073.
  • Update alpine curl to version 8.14.1-r20074.
  • Update alpine rootio-curl to version 8.14.1-r20074.
  • Update alpine curl to version 8.14.1-r20078.
  • Update alpine rootio-curl to version 8.14.1-r20078.
  • Update alpine curl to version 8.14.1-r20071.
  • Update alpine rootio-curl to version 8.14.1-r20071.
  • Update alpine curl to version 8.19.0-r00075.
  • Update alpine rootio-curl to version 8.19.0-r00075.
  • Update alpine curl to version 8.19.0-r00076.
  • Update alpine rootio-curl to version 8.19.0-r00076.
  • Update debian rootio-curl to version 8.14.1-2+deb13u4.aikido.14.
  • Update debian curl to version 8.14.1-2+deb13u4.aikido.14.
  • Update curl to version 8.14.1-r20079.
  • Update rootio-curl to version 8.14.1-r20079.
  • Update curl to version 8.14.1-2+deb13u5.aikido.18.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.18.
  • Update curl to version 8.14.1-2+deb13u5.aikido.19.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
  • Update curl to version 8.22.0-r0.
  • Update curl to version 8.21.0-r0.
  • Update curl to version 8.14.1-r30075.
  • Update rootio-curl to version 8.14.1-r30075.
  • Update curl to version 8.14.1-r200710.
  • Update rootio-curl to version 8.14.1-r200710.
  • Update curl to version 8.14.1-r30076.
  • Update rootio-curl to version 8.14.1-r30076.
  • Update curl to version 8.14.1-r20074.
  • Update rootio-curl to version 8.14.1-r20074.
  • Update curl to version 8.14.1-r200711.
  • Update rootio-curl to version 8.14.1-r200711.
  • Update curl to version 8.14.1-r30077.
  • Update rootio-curl to version 8.14.1-r30077.
  • Update curl to version 8.14.1-r20075.
  • Update rootio-curl to version 8.14.1-r20075.
  • Update curl to version 8.14.1-2+deb13u5.aikido.20.
  • Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
  • Update haxx curl to version 8.21.0 or later.
Affected software
Ecosystem VendorProductAffected versions
Ubuntu:25.10 canonical curl < 8.14.1-2ubuntu1.4
Fix: upgrade to 8.14.1-2ubuntu1.4
Ubuntu:26.04:LTS canonical curl < 8.18.0-1ubuntu2.2
Fix: upgrade to 8.18.0-1ubuntu2.2
– curl curl <= 8.20.0
< 8.14.2
< 4ae1d7cc2643e4773a136395f12bc02fc6867854
8.20.0
Alpaquita:stream bellsoft curl >= 8.1.2-r0, < 8.21.0-r0
Fix: upgrade to 8.21.0-r0
Debian:13 debian curl All versions
Debian:14 debian curl < 8.21.0~rc2-1
Fix: upgrade to 8.21.0~rc2-1
Root:Alpine:3.23 alpine curl < 8.19.0-r00074
< 8.19.0-r00075
< 8.19.0-r00076
Fix: upgrade to 8.19.0-r00074
Root:Alpine:3.23 alpine rootio-curl < 8.19.0-r00074
< 8.19.0-r00075
< 8.19.0-r00076
Fix: upgrade to 8.19.0-r00074
Root:Alpine:3.21 alpine curl < 8.14.1-r20072
< 8.14.1-r20073
Fix: upgrade to 8.14.1-r20072
Root:Alpine:3.21 alpine rootio-curl < 8.14.1-r20072
< 8.14.1-r20073
Fix: upgrade to 8.14.1-r20072
Root:Alpine:3.22 alpine curl < 8.14.1-r20073
< 8.14.1-r20074
< 8.14.1-r20071
Fix: upgrade to 8.14.1-r20073
Root:Alpine:3.22 alpine rootio-curl < 8.14.1-r20073
< 8.14.1-r20074
< 8.14.1-r20071
Fix: upgrade to 8.14.1-r20073
BellSoft Hardened Containers:stream bellsoft curl >= 8.1.2-r0, < 8.21.0-r0
Fix: upgrade to 8.21.0-r0
Root:Alpine:3.20 alpine curl < 8.14.1-r20078
Fix: upgrade to 8.14.1-r20078
Root:Alpine:3.20 alpine rootio-curl < 8.14.1-r20078
Fix: upgrade to 8.14.1-r20078
Root:Debian:13 debian rootio-curl < 8.14.1-2+deb13u4.aikido.14
Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
Root:Debian:13 debian curl < 8.14.1-2+deb13u4.aikido.14
Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
Root:Alpine:3.20 – curl < 8.14.1-r20079
< 8.14.1-r200710
< 8.14.1-r200711
Fix: upgrade to 8.14.1-r20079
Root:Alpine:3.20 – rootio-curl < 8.14.1-r20079
< 8.14.1-r200710
< 8.14.1-r200711
Fix: upgrade to 8.14.1-r20079
Root:Debian:13 – curl < 8.14.1-2+deb13u5.aikido.18
< 8.14.1-2+deb13u5.aikido.19
< 8.14.1-2+deb13u5.aikido.20
Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
Root:Debian:13 – rootio-curl < 8.14.1-2+deb13u5.aikido.18
< 8.14.1-2+deb13u5.aikido.19
< 8.14.1-2+deb13u5.aikido.20
Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
– haxx curl >= 8.11.1, < 8.21.0
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Alpine:v3.23 – curl >= 8.11.1, < 8.22.0-r0
Fix: upgrade to 8.22.0-r0
Alpine:v3.24 – curl >= 8.11.1, < 8.21.0-r0
Fix: upgrade to 8.21.0-r0
Root:Alpine:3.22 – curl < 8.14.1-r30075
< 8.14.1-r30076
< 8.14.1-r30077
Fix: upgrade to 8.14.1-r30075
Root:Alpine:3.22 – rootio-curl < 8.14.1-r30075
< 8.14.1-r30076
< 8.14.1-r30077
Fix: upgrade to 8.14.1-r30075
Root:Alpine:3.21 – curl < 8.14.1-r20074
< 8.14.1-r20075
Fix: upgrade to 8.14.1-r20074
Root:Alpine:3.21 – rootio-curl < 8.14.1-r20074
< 8.14.1-r20075
Fix: upgrade to 8.14.1-r20074
Original advisory text
CVE-2026-8926 in curl - Patched by Root
When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username (without a password), like `https://[email protected]/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
Severity
9.1 Critical
Exploitation
EPSS <1%
Type
CWE-522Insufficiently Protected Credentials
Timeline
Published24 Jun 2026
Updated27 Sep 2026
First seen24 Jun 2026
Track software like this
Free during beta