Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-10966


curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.


Published

2025-11-07T08:15:39.617

Last Modified

2026-01-20T14:57:03.173

Status

Analyzed

Source

2499f714-1537-4658-8207-48ae4bb9eae9

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application haxx curl < 8.17.0 Yes

References