CVE-2025-10966: Haxx Curl

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.

Affected products

  • Haxx Curl: from 7.69.0, before 8.17.0 (fixed in 8.17.0)

Published 2025-11-07. Last modified 2026-09-15.