Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-424 Medium 4.3

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was...

JLSEC Published
Modified
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Packages
CURL_jll < 8.17.0+0
LibCURL_jll >= 7.70.0+0, < 8.17.0+0
Aliases / Upstream
CVE-2025-10966 GHSA-5gff-h54g-38r2 EUVD-2025-38240

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.

This prevents curl from detecting MITM attackers and more.

References