curl's code for managing SSH connections when SFTP was done using the wolfSSH
powered backend was flawed and missed host verification mechanisms.
This prevents curl from detecting MITM attackers and more.
References
| Link | Resource |
|---|---|
| https://curl.se/docs/CVE-2025-10966.html | Vendor Advisory Patch |
| https://curl.se/docs/CVE-2025-10966.json | Vendor Advisory |
| https://hackerone.com/reports/3355218 | Exploit Issue Tracking Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2025/11/05/2 | Mailing List Third Party Advisory Patch |
Configurations
History
20 Jan 2026, 14:57
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://curl.se/docs/CVE-2025-10966.html - Vendor Advisory, Patch | |
| References | () https://curl.se/docs/CVE-2025-10966.json - Vendor Advisory | |
| References | () https://hackerone.com/reports/3355218 - Exploit, Issue Tracking, Third Party Advisory | |
| References | () http://www.openwall.com/lists/oss-security/2025/11/05/2 - Mailing List, Third Party Advisory, Patch | |
| CPE | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo | |
| First Time |
Haxx curl
Haxx |
10 Nov 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
07 Nov 2025, 08:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-07 08:15
Updated : 2026-01-20 14:57
NVD link : CVE-2025-10966
Mitre link : CVE-2025-10966
CVE.ORG link : CVE-2025-10966
JSON object : View
Products Affected
haxx
- curl
CWE
