Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-9547

Опубликовано: 03 июл. 2026
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 7.4

Описание

When a libcurl-based application performs transfers via SCP:// or SFTP:// and utilizes the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the known_hosts file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
jammy

released

7.81.0-1ubuntu1.25
noble

released

8.5.0-2ubuntu10.10
questing

released

8.14.1-2ubuntu1.4
resolute

released

8.18.0-1ubuntu2.2
upstream

pending

8.21.0

Показывать по

EPSS

Процентиль: 25%
0.00325
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
redhat
28 дней назад

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

CVSS3: 7.4
nvd
28 дней назад

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

msrc
25 дней назад

SSH improper host validation

CVSS3: 7.4
debian
28 дней назад

When a libcurl-based application performs transfers via `SCP://` or `S ...

CVSS3: 7.4
github
28 дней назад

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

EPSS

Процентиль: 25%
0.00325
Низкий

7.4 High

CVSS3