Security Advisory
CVE-2026-8926
9.1
CRITICAL
Vulnerability Description
When asking curl to use a `.netrc` file to find credentials and at the same
time specifying a URL with a username(without a password), like
`https://user@example.com/`, curl could wrongly get and use the password for
*another* user set in the `.netrc` file for that host if such a one exists and
there is no match for the specified user.
Published Date
July 3, 2026
Official Source
NIST NVD Advisory