CVE-2026-9547
published 2026-07-03CVE-2026-9547: When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an…
PriorityP346high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
EPSS
0.51%
39.8th percentile
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without warning and risking a potential man-in-the-middle attack.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 7.69.0 – 7.69.0 | — |
| curl | curl | 7.69.1 – 7.69.1 | — |
| curl | curl | 7.70.0 – 7.70.0 | — |
| curl | curl | 7.71.0 – 7.71.0 | — |
| curl | curl | 7.71.1 – 7.71.1 | — |
| curl | curl | 7.72.0 – 7.72.0 | — |
| curl | curl | 7.73.0 – 7.73.0 | — |
| curl | curl | 7.74.0 – 7.74.0 | — |
| curl | curl | 7.75.0 – 7.75.0 | — |
| curl | curl | 7.76.0 – 7.76.0 | — |
| curl | curl | 7.76.1 – 7.76.1 | — |
| curl | curl | 7.77.0 – 7.77.0 | — |
| curl | curl | 7.78.0 – 7.78.0 | — |
| curl | curl | 7.79.0 – 7.79.0 | — |
| curl | curl | 7.79.1 – 7.79.1 | — |
| curl | curl | 7.80.0 – 7.80.0 | — |
| curl | curl | 7.81.0 – 7.81.0 | — |
| curl | curl | 7.82.0 – 7.82.0 | — |
| curl | curl | 7.83.0 – 7.83.0 | — |
| curl | curl | 7.83.1 – 7.83.1 | — |
| curl | curl | 7.84.0 – 7.84.0 | — |
| curl | curl | 7.85.0 – 7.85.0 | — |
| curl | curl | 7.86.0 – 7.86.0 | — |
| curl | curl | 7.87.0 – 7.87.0 | — |
| curl | curl | 7.88.0 – 7.88.0 | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
curl: curl: Man-in-the-middle attack via SSH host key bypass
vendor_redhat·2026-07-03·CVSS 7.4
CVE-2026-9547 [HIGH] CWE-347 curl: curl: Man-in-the-middle attack via SSH host key bypass
curl: curl: Man-in-the-middle attack via SSH host key bypass
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without warning and risking a potential man-in-the-middle attack.
A flaw was found in curl. When a libcurl-based application uses SCP:// or SFTP:// for transfers and employs the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-06-30
CVE-2026-8286 curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Andrew Nesbitt discovered that curl could reuse an existing live
connection during STARTTLS-based connection upgrades even when the TLS
configuration did not match. A remote attacker could possibly use this
issue to cause curl to use an unintended TLS configuration.
(CVE-2026-8286)
Muhamad Arga Reksapati discovered that curl incorrectly reused
connections for Negotiate-authenticated requests when different services
were involved. A remote attacker could possibly use this issue to access
resources authenticated for another service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-8458)
It was discovered that curl i
GHSA
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server.
ghsa_unreviewed·2026-07-03
CVE-2026-9547 When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server.
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without warning and risking a potential man-in-the-middle attack.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
bugzilla·2026-07-06·CVSS 7.4
CVE-2026-9547 [HIGH] CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without wa
Bugzilla
CVE-2026-9547 mingw-curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
bugzilla·2026-07-06·CVSS 7.4
CVE-2026-9547 [HIGH] CVE-2026-9547 mingw-curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
CVE-2026-9547 mingw-curl: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed with
Bugzilla
CVE-2026-9547 rpi-imager: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
bugzilla·2026-07-06·CVSS 7.4
CVE-2026-9547 [HIGH] CVE-2026-9547 rpi-imager: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
CVE-2026-9547 rpi-imager: curl: Man-in-the-middle attack via SSH host key bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed with
Bugzilla
CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass
bugzilla·2026-07-03·CVSS 7.4
CVE-2026-9547 [HIGH] CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass
CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without warning and risking a potential man-in-the-middle attack.
2026-07-03
Published