https://seclists.org/oss-sec/2025/q4/137: [SECURITY ADVISORY] curl: missing SFTP host verification with wolfSSH
Published Nov 5, 2025
·Updated
Affected Software
1 affected component
curl curl
Frequently Asked Questions
1
What is the severity of CVE-2025-10966?
CVE-2025-10966 is considered a medium severity vulnerability due to the potential risk of man-in-the-middle attacks.
2
How do I fix CVE-2025-10966?
To fix CVE-2025-10966, update curl to a version that includes the patch for missing SFTP host verification.
3
What does CVE-2025-10966 affect?
CVE-2025-10966 affects curl's SFTP functionality when using the wolfSSH backend for SSH connections.
4
What are the potential consequences of CVE-2025-10966?
The consequences of CVE-2025-10966 include possible exposure to man-in-the-middle attacks if SFTP host verification is bypassed.
5
Is there a workaround for CVE-2025-10966?
A temporary workaround for CVE-2025-10966 is to avoid using SFTP with curl until an update is applied.