CVE-2025-10966
Modified
Modified - Updated After Analysis
BaseFortify
Publication date: 2025-11-07
Last updated on: 2026-06-02
Assigner: curl
Description
Description
curl's code for managing SSH connections when SFTP was done using the wolfSSH
powered backend was flawed and missed host verification mechanisms.
This prevents curl from detecting MITM attackers and more.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| curl | curl | 7.69.0 |
| curl | curl | 8.16.0 |
| curl | curl | 8.17.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |