CVE-2025-15079
Not scored
libssh global known_hosts override
When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.
Exploit probability
0.5%
Published
January 8, 2026
Required by
Not available
Last source change
July 15, 2026
02 / AFFECTED SOFTWARE
Affected packages
73 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2025-15079
View original source
When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2026/01/07/6
- https://curl.se/docs/CVE-2025-15079.html
- https://curl.se/docs/CVE-2025-15079.json
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15079.json
- https://hackerone.com/reports/3477116
- https://nvd.nist.gov/vuln/detail/CVE-2025-15079