cbcvebase.
CVE-2026-12064
published 2026-07-03

CVE-2026-12064: When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool…

PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.57%
43.4th percentile
When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
curlcurl7.81.0 – 7.81.0
curlcurl7.82.0 – 7.82.0
curlcurl7.83.0 – 7.83.0
curlcurl7.83.1 – 7.83.1
curlcurl7.84.0 – 7.84.0
curlcurl7.85.0 – 7.85.0
curlcurl7.86.0 – 7.86.0
curlcurl7.87.0 – 7.87.0
curlcurl7.88.0 – 7.88.0
curlcurl7.88.1 – 7.88.1
curlcurl8.0.0 – 8.0.0
curlcurl8.0.1 – 8.0.1
curlcurl8.1.0 – 8.1.0
curlcurl8.1.1 – 8.1.1
curlcurl8.1.2 – 8.1.2
curlcurl8.10.0 – 8.10.0
curlcurl8.10.1 – 8.10.1
curlcurl8.11.0 – 8.11.0
curlcurl8.11.1 – 8.11.1
curlcurl8.12.0 – 8.12.0
curlcurl8.12.1 – 8.12.1
curlcurl8.13.0 – 8.13.0
curlcurl8.14.0 – 8.14.0
curlcurl8.14.1 – 8.14.1
curlcurl8.15.0 – 8.15.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.5HIGH
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.