https://seclists.org/oss-sec/2026/q1/35: [ADVISORY] curl CVE-2025-15079: libssh global knownhost override
Published Jan 7, 2026
·Updated
Affected Software
1 affected component
redhat/curl>=7.58.0<=8.17.0
Frequently Asked Questions
1
What is the severity of CVE-2025-15079?
CVE-2025-15079 is considered a moderate severity vulnerability due to its potential to allow unauthorized access during SSH-based transfers.
2
How do I fix CVE-2025-15079?
To fix CVE-2025-15079, update libcurl to the latest version that addresses this vulnerability.
3
What impact does CVE-2025-15079 have on SSH transfers?
CVE-2025-15079 can lead to global knownhost overrides, potentially compromising the security of SSH-based file transfers like SCP and SFTP.
4
Is CVE-2025-15079 a result of misconfiguration?
No, CVE-2025-15079 is a flaw in libcurl that affects how knownhosts files are handled during SSH-based transfers.
5
Which versions of curl are affected by CVE-2025-15079?
CVE-2025-15079 affects specific versions of libcurl that utilize the affected functions without the appropriate security checks.