---
schema_version: '1.0'
id: security-20260705-35fa1f
url: https://osv.dev/vulnerability/CVE-2025-10966
url_hash: 35fa1fb51100317caa2bcac8d9b1300fa9d264c6da55f4505b0e60803a304a08
canonical_url: https://osv.dev/vulnerability/CVE-2025-10966
source: osv:nvd
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2025-10966
- severity:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- https://github.com/curl/curl
- GIT
lang: en
published_at: '2025-11-07T08:15:39Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-08T15:37:32Z'
status: published
content_hash: 16d83ec3c7cbf135a033ec0d18b41762bcb2023ae46218bea94a613a6e4f8969
license_note: full
summary: missing SFTP host verification with wolfSSH
summary_source: rss
summary_en: missing SFTP host verification with wolfSSH
entities:
- name: CVE-2013-0074
  type: naturalobject
- name: GitHub
  type: organization
- name: ghost
  type: artifact
- name: Verification
  type: method
- name: aligned with
  type: UNKNOWN
related_auto:
- name: agent_openclaw
  type: person
  weight: 1.0
- name: CVSS score
  type: concept
  weight: 1.0
- name: AI Agent
  type: artifact
  weight: 1.0
- name: Hy3
  type: artifact
  weight: 1.0
- name: OpenClaw
  type: artifact
  weight: 1.0
title: CVE-2025-10966 — https://github.com/curl/curl
---

# CVE-2025-10966: missing SFTP host verification with wolfSSH

## TL;DR
missing SFTP host verification with wolfSSH

## Key Points
- cve / CVE-2025-10966 / severity:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N / https://github.com/curl/curl / GIT

## Details
**Severity:** CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
**Advisory:** CVE-2025-10966

**Affected (your watchlist):**
- `GIT:https://github.com/curl/curl` curl-8_9_1 → no fixed version listed [mac]

**Details:**
curl's code for managing SSH connections when SFTP was done using the wolfSSH
powered backend was flawed and missed host verification mechanisms.

This prevents curl from detecting MITM attackers and more.

**References:**
- http://www.openwall.com/lists/oss-security/2025/11/05/2
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
- https://curl.se/docs/CVE-2025-10966.html
- https://curl.se/docs/CVE-2025-10966.json
- https://hackerone.com/reports/3355218
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/10xxx/CVE-2025-10966.json
- https://nvd.nist.gov/vuln/detail/CVE-2025-10966

_Data: OSV.dev (upstream: nvd) — https://osv.dev/vulnerability/CVE-2025-10966_

## Source
元記事: [CVE-2025-10966: missing SFTP host verification with wolfSSH](https://osv.dev/vulnerability/CVE-2025-10966) — published 2025-11-07T08:15:39Z
