https://seclists.org/oss-sec/2026/q1/36: [ADVISORY] curl CVE-2025-15224: libssh key passphrase bypass without agent set
Published Jan 7, 2026
·Updated
Affected Software
1 affected component
redhat/libcurl>=7.58.0<=8.17.0
Frequently Asked Questions
1
What is the severity of CVE-2025-15224?
CVE-2025-15224 has a medium severity rating, indicating potential risks during SSH-based transfers.
2
How do I fix CVE-2025-15224?
To fix CVE-2025-15224, ensure you are using a patched version of libcurl that addresses the key passphrase bypass issue.
3
What systems are affected by CVE-2025-15224?
CVE-2025-15224 affects systems using the libcurl library for SSH-based transfers including SCP and SFTP.
4
What type of attacks can exploit CVE-2025-15224?
CVE-2025-15224 can be exploited by attackers to bypass passphrase protections when using SSH keys without an agent.
5
When was CVE-2025-15224 disclosed?
CVE-2025-15224 was disclosed on January 7, 2026, as part of a security advisory by Project curl.