FlawAtlas
Search the atlas
CVE-2025-15079 Not scored

libssh global known_hosts override

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.

Exploit probability 0.5%
Published January 8, 2026
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

73 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:10017-1
related OPENSUSE-SU-2026:20031-1
related SUSE-SU-2026:0050-1
related SUSE-SU-2026:0051-1
related SUSE-SU-2026:0052-1
related SUSE-SU-2026:0066-1
related SUSE-SU-2026:0508-1
related SUSE-SU-2026:20042-1
related SUSE-SU-2026:20062-1
related SUSE-SU-2026:20082-1
related SUSE-SU-2026:20110-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-15079

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.

View original source

05 / REFERENCES

Further evidence