CVE Vulnerabilities

CVE-2025-15224

Improper Authentication

Published: Jan 08, 2026 | Modified: Jan 20, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
LOW

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Curl Haxx 7.58.0 (including) 8.18.0 (excluding)
Curl Ubuntu esm-infra/bionic *
Curl Ubuntu esm-infra/focal *
Curl Ubuntu jammy *
Curl Ubuntu noble *
Curl Ubuntu upstream *

Potential Mitigations

References