curl vulnerability

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

Published 7 Nov 2025Updated 15 Sep 20267 sources
CVSS 4.3 ✓ VERIFIED REFERENCE

Source timeline

CVE record published by NVDView source ↗