4.3
CVE-2025-10966
- EPSS 0.4%
- Veröffentlicht 07.11.2025 07:26:30
- Zuletzt bearbeitet 15.09.2026 07:16:23
- Erkennungen
missing SFTP host verification with wolfSSH
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.327 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-322 Key Exchange without Entity Authentication
The product performs a key exchange with an actor without verifying the identity of that actor.
https://hackerone.com/reports/3355218
http://www.openwall.com/lists/oss-security/2025/11/05/2
https://cert-portal.siemens.com/productcert/html/ssa-253495.html
https://curl.se/docs/CVE-2025-10966.html
https://curl.se/docs/CVE-2025-10966.json