Beveiligingsadvies

CVE-2026-8926

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-03 06:15:45
Laatst bijgewerkt 2026-07-06 17:02:33
Toegewezen door curl
CVSS-score 9.1
Status PUBLISHED

Beschrijving

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.