VYPR
Unrated severityNVD Advisory· Published Nov 7, 2025· Updated Nov 10, 2025

missing SFTP host verification with wolfSSH

CVE-2025-10966

Description

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.

This prevents curl from detecting MITM attackers and more.

Affected products

2
  • Curl/Curlllm-fuzzy2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 8.16.0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.