openwrt ▾
›
openwrt-25.12 ▾
›
vulnerability
›
CVE-2025-10966
Component Overview
Vulnerability Overview
Name
CVE-2025-10966
Source
NVD (
link
)
Debian (
link
)
Description
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
CWEs
Published Date
Nov 7, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://curl.se/docs/CVE-2025-10966.html
Patch
https://curl.se/docs/CVE-2025-10966.json
Vendor Advisory
https://hackerone.com/reports/3355218
Exploit
http://www.openwall.com/lists/oss-security/2025/11/05/2
Mailing List
Analysis
#
Affected Component
Analysis
libcurl-gnutls
Exploitable
Vulnerability Ratings
#
4.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libcurl
buildroot
2025.02.x
8.20.0
Not Affected
libcurl
buildroot
master
8.21.0
Not Affected
curl
openwrt
master
8.19.0-r2
Not Affected
libcurl-gnutls
openwrt
master
8.20.0-r1
Not Affected
curl
yocto
kirkstone
7.82.0
Exploitable
curl
yocto
master
8.20.0
Not Affected
curl
yocto
scarthgap
8.7.1
False Positive