Security Flaw in libcurl Affects SSH File Transfers
CVE-2025-15079
5.3MEDIUM
What is CVE-2025-15079?
A security vulnerability in libcurl allows for insecure SSH-based file transfers using SCP or SFTP. If users configure a known_hosts file, libcurl may still erroneously accept connections to hosts not included in that file if those hosts are present in the libssh global known_hosts database. This oversight could expose users to potential threats by unintentionally connecting to unverified hosts, thereby compromising the integrity and confidentiality of file transfers.
Affected Version(s)
curl 8.17.0
curl 8.16.0
curl 8.15.0
