curl vulnerability

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

Published 7 Nov 2025Updated 15 Sep 20267 sources
CVSS 4.3 ✓ VERIFIED REFERENCE

What happened

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

Affected versions

curl: 7.69.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 6773c7ca65cf2183295e56603f9b86a5ce816a06 through before b011e3fcfb06d6c0278595ee2ee297036fbe9793 (git); 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0; before V4.0 (custom) Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

RepositoryAuthorFirst seenReference
hackerone.comNVD reference2025-11-07Verified