VYPR
Critical severity9.1NVD Advisory· Published Jul 3, 2026· Updated Sep 15, 2026

CVE-2026-8926

CVE-2026-8926

Description

When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username (without a password), like https://[email protected]/, curl could wrongly get and use the password for *another* user set in the .netrc file for that host if such a one exists and there is no match for the specified user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

18

Patches

Vulnerability mechanics

References

3

News mentions

2