UBUNTU-CVE-2026-8926

Source
https://ubuntu.com/security/CVE-2026-8926
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8926.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-8926
Upstream
  • CVE-2026-8926
Downstream
Related
Published
2026-06-24T14:00:00Z
Modified
2026-07-02T22:49:53.927768351Z
Severity
  • Ubuntu - low
Summary
[none]
Details

When asking curl to use a .netrc file to find credentials and at the same time specifying a URL with a username (without a password), like https://user@example.com/, curl could wrongly get and use the password for another user set in the .netrc file for that host if such a one exists and there is no match for the specified user.

References

Affected packages

Ubuntu:25.10 / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.14.1-2ubuntu1.4

Affected versions

8.*
8.12.1-3ubuntu1
8.13.0-5ubuntu1
8.14.1-1ubuntu2
8.14.1-1ubuntu3
8.14.1-2ubuntu1
8.14.1-2ubuntu1.1
8.14.1-2ubuntu1.2
8.14.1-2ubuntu1.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "curl",
            "binary_version": "8.14.1-2ubuntu1.4"
        },
        {
            "binary_name": "libcurl3t64-gnutls",
            "binary_version": "8.14.1-2ubuntu1.4"
        },
        {
            "binary_name": "libcurl4t64",
            "binary_version": "8.14.1-2ubuntu1.4"
        }
    ],
    "priority_reason": "Upstream defined this as low severity",
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8926.json"

Ubuntu:26.04:LTS / curl

Package

Name
curl
Purl
pkg:deb/ubuntu/curl?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8.18.0-1ubuntu2.2

Affected versions

8.*
8.14.1-2ubuntu1
8.17.0-1ubuntu1
8.18.0-1ubuntu1
8.18.0-1ubuntu2
8.18.0-1ubuntu2.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "curl",
            "binary_version": "8.18.0-1ubuntu2.2"
        },
        {
            "binary_name": "libcurl3t64-gnutls",
            "binary_version": "8.18.0-1ubuntu2.2"
        },
        {
            "binary_name": "libcurl4t64",
            "binary_version": "8.18.0-1ubuntu2.2"
        }
    ],
    "priority_reason": "Upstream defined this as low severity",
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-8926.json"