Security Flaw in libcurl Affects SSH File Transfers
CVE-2025-15079

5.3MEDIUM

Key Information:

Vendor

Curl

Status
Vendor
CVE Published:
8 January 2026

What is CVE-2025-15079?

A security vulnerability in libcurl allows for insecure SSH-based file transfers using SCP or SFTP. If users configure a known_hosts file, libcurl may still erroneously accept connections to hosts not included in that file if those hosts are present in the libssh global known_hosts database. This oversight could expose users to potential threats by unintentionally connecting to unverified hosts, thereby compromising the integrity and confidentiality of file transfers.

Affected Version(s)

curl 8.17.0

curl 8.16.0

curl 8.15.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harry Sintonen
Daniel Stenberg
.