IM
IronMonkey Threat Research

CVE-2025-10966 MEDIUM

Published: 2025-11-07 | Last Modified: 2026-06-02 | Status: Modified

Description

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

CVSS Metrics

Base Score: 4.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactNONE

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Type: Secondary

Exploitability Score: 2.8

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
haxx curl * <built-in method update of dict object at 0x7f76011b2b00> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

References

Notification
Message here