CVE Vulnerabilities

CVE-2025-10966

Key Exchange without Entity Authentication

Published: Nov 07, 2025 | Modified: Sep 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.9 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

curls code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.

This prevents curl from detecting MITM attackers and more.

Weakness

The product performs a key exchange with an actor without verifying the identity of that actor.

Affected Software

NameVendorStart VersionEnd Version
CurlHaxx7.69.0 (including)8.17.0 (excluding)
Red Hat Hardened ImagesRedHatcurl-main-8.19.0-3.hum1*
CurlUbuntuupstream*

Potential Mitigations

References