curl vulnerability

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

Published 3 Jul 2026Updated 15 Sep 20266 sources
CVSS 7.4 ✓ VERIFIED REFERENCE

What happened

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

Affected versions

curl: 7.69.0 through before 8.14.2 (semver); 8.15.0 through before 8.16.1 (semver); 8.17.0 through before 8.20.1 (semver); 507cf6a13db0375eadd4655b4c64710db29e9cf2 through before 0b8dbbc63c98777e4584cb9fbd71df3464008ad1 (git); 8.20.0; 8.19.0; 8.18.0; 8.17.0; 8.16.0; 8.15.0; 8.14.1; 8.14.0; 8.13.0; 8.12.1; 8.12.0; 8.11.1; 8.11.0; 8.10.1; 8.10.0; 8.9.1; 8.9.0; 8.8.0; 8.7.1; 8.7.0; 8.6.0; 8.5.0; 8.4.0; 8.3.0; 8.2.1; 8.2.0; 8.1.2; 8.1.1; 8.1.0; 8.0.1; 8.0.0; 7.88.1; 7.88.0; 7.87.0; 7.86.0; 7.85.0; 7.84.0; 7.83.1; 7.83.0; 7.82.0; 7.81.0; 7.80.0; 7.79.1; 7.79.0; 7.78.0; 7.77.0; 7.76.1; 7.76.0; 7.75.0; 7.74.0; 7.73.0; 7.72.0; 7.71.1; 7.71.0; 7.70.0; 7.69.1; 7.69.0 Fixed: See vendor advisory.

Why it matters

Review the vendor advisory and exposure of the affected product to determine operational impact.

Detection & mitigation

  • Apply vendor-provided updates or mitigations.
  • Review affected product exposure and access logs.

Public PoC references

RepositoryAuthorFirst seenReference
hackerone.comNVD reference2026-07-03Verified