REDHAT-BUG-2496758: High severity libcurl vulnerability

Published Jul 3, 2026
·
Updated

When a libcurl-based application performs transfers via SCP:// or SFTP:// and utilizes the CURLOPTSSHKEYFUNCTION callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the knownhosts file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

Affected Software

1 affected component
libcurl

Event History

Jul 3, 2026
Data Sourced
via Red Hat·07:01 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Applications built on libcurl are affected when they perform SCP:// or SFTP:// transfers and use the CURLOPT_SSH_KEYFUNCTION callback. The issue concerns validation of server host keys recorded in known_hosts.

2

What would an attacker need to exploit this?

An attacker would need to present an untrusted server host key whose type differs from the key type already recorded for that host in known_hosts. Under the affected callback handling, the connection may succeed without a warning, enabling a potential man-in-the-middle attack.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203