curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and…
Medium CVSS 4.3
Summary
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://curl.se/docs/CVE-2025-10966.html Patch
- https://curl.se/docs/CVE-2025-10966.json Vendor Advisory
- https://hackerone.com/reports/3355218 Exploit
- http://www.openwall.com/lists/oss-security/2025/11/05/2 Mailing List
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
Timeline
- nvd_ingest NVD