Количество 14
Количество 14
CVE-2026-9547
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
CVE-2026-9547
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
CVE-2026-9547
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
CVE-2026-9547
SSH improper host validation
CVE-2026-9547
When a libcurl-based application performs transfers via `SCP://` or `S ...
GHSA-xq9p-gxg6-f7q6
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
RLSA-2026:55439
Important: curl security update
ELSA-2026-55439
ELSA-2026-55439: curl security update (IMPORTANT)
SUSE-SU-2026:3814-1
Security update for curl
ELSA-2026-55450
ELSA-2026-55450: curl security update (IMPORTANT)
openSUSE-SU-2026:21272-1
Security update for curl
SUSE-SU-2026:3043-1
Security update for curl
SUSE-SU-2026:2926-1
Security update for curl
SUSE-SU-2026:2925-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-9547 When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack. | CVSS3: 7.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-9547 When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack. | CVSS3: 7.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-9547 When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack. | CVSS3: 7.4 | 0% Низкий | 2 месяца назад | |
CVE-2026-9547 SSH improper host validation | 0% Низкий | 2 месяца назад | ||
CVE-2026-9547 When a libcurl-based application performs transfers via `SCP://` or `S ... | CVSS3: 7.4 | 0% Низкий | 2 месяца назад | |
GHSA-xq9p-gxg6-f7q6 When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack. | CVSS3: 7.4 | 0% Низкий | 2 месяца назад | |
RLSA-2026:55439 Important: curl security update | 29 дней назад | |||
ELSA-2026-55439 ELSA-2026-55439: curl security update (IMPORTANT) | 29 дней назад | |||
SUSE-SU-2026:3814-1 Security update for curl | 20 дней назад | |||
ELSA-2026-55450 ELSA-2026-55450: curl security update (IMPORTANT) | 29 дней назад | |||
openSUSE-SU-2026:21272-1 Security update for curl | 2 месяца назад | |||
SUSE-SU-2026:3043-1 Security update for curl | 2 месяца назад | |||
SUSE-SU-2026:2926-1 Security update for curl | 2 месяца назад | |||
SUSE-SU-2026:2925-1 Security update for curl | 2 месяца назад |
Уязвимостей на страницу