CVE-2025-10966

Published: November 6, 2025Last modified: December 15, 2025

Description

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

Severity score breakdown

ParameterValue
Base score4.3
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityLOW
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTScurlFixed (8.9.1-r4)
25 LTScurlFixed (8.14.1-r3)
StreamcurlFixed (8.17.0-r0)
Hardened ContainersStreamcurlFixed (8.17.0-r0)

References

ON THIS PAGE