{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/rhel7els/vex/2026/cve-2026-8926-els_os-rhel7els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T15:53:47Z",
      "generator": {
        "date": "2026-07-28T15:53:47Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-8926-ELS_OS-RHEL7ELS",
      "initial_release_date": "2026-07-03T07:16:00Z",
      "revision_history": [
        {
          "date": "2026-07-03T07:16:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T15:53:47Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2026-8926"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux 7",
                "product": {
                  "name": "Red Hat Enterprise Linux 7",
                  "product_id": "Red-Hat-7",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:redhat:enterprise_linux:7:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "curl-0:7.29.0-59.0.3.el7_9.2.x86_64",
                "product": {
                  "name": "curl-0:7.29.0-59.0.3.el7_9.2.x86_64",
                  "product_id": "curl-0:7.29.0-59.0.3.el7_9.2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/curl@7.29.0-59.0.3.el7_9.2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64",
                "product": {
                  "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64",
                  "product_id": "libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/libcurl@7.29.0-59.0.3.el7_9.2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64",
                "product": {
                  "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64",
                  "product_id": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/libcurl-devel@7.29.0-59.0.3.el7_9.2?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.i686",
                "product": {
                  "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.i686",
                  "product_id": "libcurl-0:7.29.0-59.0.3.el7_9.2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/libcurl@7.29.0-59.0.3.el7_9.2?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686",
                "product": {
                  "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686",
                  "product_id": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/libcurl-devel@7.29.0-59.0.3.el7_9.2?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                "product": {
                  "name": "curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                  "product_id": "curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/curl@7.29.0-59.0.3.el7_9.2.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                "product": {
                  "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                  "product_id": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libcurl@7.29.0-59.0.3.el7_9.2.tuxcare.els2?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                "product": {
                  "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                  "product_id": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libcurl-devel@7.29.0-59.0.3.el7_9.2.tuxcare.els2?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
                "product": {
                  "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
                  "product_id": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libcurl@7.29.0-59.0.3.el7_9.2.tuxcare.els2?arch=i686"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
                "product": {
                  "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
                  "product_id": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/libcurl-devel@7.29.0-59.0.3.el7_9.2.tuxcare.els2?arch=i686"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64"
        },
        "product_reference": "curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "curl-0:7.29.0-59.0.3.el7_9.2.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:curl-0:7.29.0-59.0.3.el7_9.2.x86_64"
        },
        "product_reference": "curl-0:7.29.0-59.0.3.el7_9.2.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686"
        },
        "product_reference": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.i686"
        },
        "product_reference": "libcurl-0:7.29.0-59.0.3.el7_9.2.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64"
        },
        "product_reference": "libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64"
        },
        "product_reference": "libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64"
        },
        "product_reference": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64"
        },
        "product_reference": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686"
        },
        "product_reference": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
        "relates_to_product_reference": "Red-Hat-7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686 as a component of Red Hat Enterprise Linux 7",
          "product_id": "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686"
        },
        "product_reference": "libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686",
        "relates_to_product_reference": "Red-Hat-7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-8926",
      "cwe": {
        "id": "CWE-289",
        "name": "Authentication Bypass by Alternate Name"
      },
      "notes": [
        {
          "category": "description",
          "text": "When asking curl to use a `.netrc` file to find credentials and at the same\ntime specifying a URL with a username(without a password), like\n`https://user@example.com/`, curl could wrongly get and use the password for\n*another* user set in the `.netrc` file for that host if such a one exists and\nthere is no match for the specified user.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Red-Hat-7:curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
          "Red-Hat-7:curl-0:7.29.0-59.0.3.el7_9.2.x86_64",
          "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.i686",
          "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
          "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
          "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64",
          "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686",
          "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
          "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
          "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-8926"
        }
      ],
      "release_date": "2026-07-03T07:16:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T11:58:23.904247Z",
          "details": "Low practical risk: this bug only triggers when curl is explicitly told to use a .netrc file and the URL embeds a username without a password while the .netrc has a different user defined for the same host—conditions that are non-default and require deliberate user interaction. Even then, the exposure is limited to sending an existing password to the same host already being contacted (typically over TLS), with no code execution, integrity change, availability impact, or privilege escalation. In centrally managed server/VM workflows where curl invocations are scripted and parameters are fixed, this precise invocation pattern is unlikely, so the issue can be safely deprioritized.",
          "product_ids": [
            "Red-Hat-7:curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
            "Red-Hat-7:curl-0:7.29.0-59.0.3.el7_9.2.x86_64",
            "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.i686",
            "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
            "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
            "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64",
            "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686",
            "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
            "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
            "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 4.8,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Red-Hat-7:curl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
            "Red-Hat-7:curl-0:7.29.0-59.0.3.el7_9.2.x86_64",
            "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.i686",
            "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
            "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
            "Red-Hat-7:libcurl-0:7.29.0-59.0.3.el7_9.2.x86_64",
            "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.i686",
            "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.i686",
            "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.tuxcare.els2.x86_64",
            "Red-Hat-7:libcurl-devel-0:7.29.0-59.0.3.el7_9.2.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}