Security Advisory

CVE-2025-10966

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-07 07:26:30
Last updated 2026-06-02 12:59:51
Assigner curl
CVSS score not scored
State PUBLISHED

Description

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.