CVE-2026-12064
published 2026-07-03CVE-2026-12064: When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.57%
43.4th percentile
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the
libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes
the connection via SFTP/SCP as specified. Because the tool layer skipped the
security configuration, these SSH host verification options are silently
omitted, causing curl to connect to an unverified SSH remote host without
throwing an error.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 7.81.0 – 7.81.0 | — |
| curl | curl | 7.82.0 – 7.82.0 | — |
| curl | curl | 7.83.0 – 7.83.0 | — |
| curl | curl | 7.83.1 – 7.83.1 | — |
| curl | curl | 7.84.0 – 7.84.0 | — |
| curl | curl | 7.85.0 – 7.85.0 | — |
| curl | curl | 7.86.0 – 7.86.0 | — |
| curl | curl | 7.87.0 – 7.87.0 | — |
| curl | curl | 7.88.0 – 7.88.0 | — |
| curl | curl | 7.88.1 – 7.88.1 | — |
| curl | curl | 8.0.0 – 8.0.0 | — |
| curl | curl | 8.0.1 – 8.0.1 | — |
| curl | curl | 8.1.0 – 8.1.0 | — |
| curl | curl | 8.1.1 – 8.1.1 | — |
| curl | curl | 8.1.2 – 8.1.2 | — |
| curl | curl | 8.10.0 – 8.10.0 | — |
| curl | curl | 8.10.1 – 8.10.1 | — |
| curl | curl | 8.11.0 – 8.11.0 | — |
| curl | curl | 8.11.1 – 8.11.1 | — |
| curl | curl | 8.12.0 – 8.12.0 | — |
| curl | curl | 8.12.1 – 8.12.1 | — |
| curl | curl | 8.13.0 – 8.13.0 | — |
| curl | curl | 8.14.0 – 8.14.0 | — |
| curl | curl | 8.14.1 – 8.14.1 | — |
| curl | curl | 8.15.0 – 8.15.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.5HIGH
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-07-09·CVSS 3.4
CVE-2026-11352 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen discovered that curl incorrectly handled credentials when
following HTTP redirects in conjunction with .netrc files. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-11053)
Hiroki Kurosawa discovered that curl incorrectly handled OCSP stapling
responses. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2024-8096)
Joshua Rogers discovered that curl had a use-after-free vulnerability when
resetting and cleaning up HTTP/2 stream handles. An attacker could possibly
use this issue
Red Hat
curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
vendor_redhat·2026-07-03·CVSS 7.5
CVE-2026-12064 [HIGH] CWE-358 curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the
libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes
the connection via SFTP/SCP as specified. Because the tool layer skipped the
security configuration, these SSH host verification options are silently
omitted, causing curl to connect to an unverified SSH remote host without
throwing an error.
A flaw was found in curl. When a
GHSA
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl.
ghsa_unreviewed·2026-07-03
CVE-2026-12064 When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl.
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the
libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes
the connection via SFTP/SCP as specified. Because the tool layer skipped the
security configuration, these SSH host verification options are silently
omitted, causing curl to connect to an unverified SSH remote host without
throwing an error.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-12064 curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-12064 [HIGH] CVE-2026-12064 curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
CVE-2026-12064 curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the
libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes
the connection via SFTP
Bugzilla
CVE-2026-12064 rpi-imager: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-12064 [HIGH] CVE-2026-12064 rpi-imager: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
CVE-2026-12064 rpi-imager: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the
libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes
the connection vi
Bugzilla
CVE-2026-12064 mingw-curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
bugzilla·2026-07-06·CVSS 7.5
CVE-2026-12064 [HIGH] CVE-2026-12064 mingw-curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
CVE-2026-12064 mingw-curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the
libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes
the connection vi
Bugzilla
CVE-2026-12064 curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
bugzilla·2026-07-03·CVSS 7.5
CVE-2026-12064 [HIGH] CVE-2026-12064 curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
CVE-2026-12064 curl: curl: SSH host verification bypass when using schemeless URLs with SFTP/SCP
When a user invokes curl using a schemeless URL combined with
`--proto-default` sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the
libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes
the connection via SFTP/SCP as specified. Because the tool layer skipped the
security configuration, these SSH host verification options are silently
omitted, causing curl to connect to an unverified SSH remote host without
throwing an error.
2026-07-03
Published