ZeroHour

CVE-2025-10966

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p33
Published
()
Modified
Description

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

Vendors
haxx
Products
curl
Weakness
CWE-322
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.