Skip to main content

Key Exchange without Entity Authentication

CVE-2025-10966

Severity Medium
Score 4.3/10

Summary

Curl's code for managing SSH connections when SFTP was done using the wolfSSH-powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more. Affected versions are from 7.69.0 through 8.16.0.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-322 - Key Exchange without Entity Authentication

The software performs a key exchange with an actor without verifying the identity of that actor.

Advisory Timeline

  • Published