{"id":"JLSEC-2026-1341","details":"curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the readworks, write a zero byte beyond its boundary.This will in most cases cause a segfault or similar, but circumstances might also cause different outcomes.If a malicious user can provide a custom netrc file to an application or otherwise affect its contents, this flaw could be used as denial-of-service.","modified":"2026-08-17T13:30:04.501946357Z","published":"2026-08-17T13:15:13.400Z","upstream":["CVE-2022-35260"],"database_specific":{"license":"CC-BY-4.0","sources":[{"modified":"2026-06-17T04:51:40.673Z","published":"2022-12-05T22:15:10.743Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2022-35260","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35260","database_specific":{"status":"Modified"},"id":"CVE-2022-35260","imported":"2026-08-16T08:05:12.989Z"}]},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2023/Jan/19"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2023/Jan/19"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2023/Jan/20"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2023/Jan/20"},{"type":"WEB","url":"https://hackerone.com/reports/1721098"},{"type":"WEB","url":"https://hackerone.com/reports/1721098"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202212-01"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202212-01"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230110-0006/"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20230110-0006/"},{"type":"WEB","url":"https://support.apple.com/kb/HT213604"},{"type":"WEB","url":"https://support.apple.com/kb/HT213604"},{"type":"WEB","url":"https://support.apple.com/kb/HT213605"},{"type":"WEB","url":"https://support.apple.com/kb/HT213605"}],"affected":[{"package":{"name":"LibCURL_jll","ecosystem":"Julia","purl":"pkg:julia/LibCURL_jll?uuid=deac9b47-8bc7-5906-a0fe-35ac56dc84c0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.84.0+0"},{"fixed":"7.87.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1341.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","source":"NVD"}]}