Logo
vulnerabilityCVE-2025-10966
Name
CVE-2025-10966
Source
NVD ( link)Debian ( link)
Description
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
CWEs
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
curl
False Positive

Vulnerability Ratings#


4.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
8.20.0
Not Affected
buildroot
master
8.21.0
Not Affected
openwrt
master
8.19.0-r2
Not Affected
openwrt
master
8.20.0-r1
Not Affected
openwrt
openwrt-25.12
8.19.0-r2
Not Affected
openwrt
openwrt-25.12
8.14.1-r1
Exploitable
yocto
kirkstone
7.82.0
Exploitable
yocto
master
8.20.0
Not Affected