CVE-2025-10966
Not scored
missing SFTP host verification with wolfSSH
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
Exploit probability
0.4%
Published
November 7, 2025
Required by
Not available
Last source change
July 15, 2026
02 / AFFECTED SOFTWARE
Affected packages
53 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2025-10966
View original source
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2025/11/05/2
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
- https://curl.se/docs/CVE-2025-10966.html
- https://curl.se/docs/CVE-2025-10966.json
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10966.json
- https://hackerone.com/reports/3355218
- https://nvd.nist.gov/vuln/detail/CVE-2025-10966