curl's code for managing SSH connections when SFTP was done using the wolfSSH
powered backend was flawed and missed host verification mechanisms.
This prevents curl from detecting MITM attackers and more.
References
Configurations
No configuration.
History
10 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
07 Nov 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-07 08:15
Updated : 2025-11-12 16:20
NVD link : CVE-2025-10966
Mitre link : CVE-2025-10966
CVE.ORG link : CVE-2025-10966
JSON object : View
Products Affected
No product.
CWE
No CWE.
