VDB
ALPINE-CVE-2025-10966
ALPINE-CVE-2025-10966
PUBLISHED
CVSS 4.300000190734863 MEDIUM
curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms. This prevents curl from detecting MITM attackers and more.
Risk Scores
CVSS v3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.23 | curl | 7.19.2-r1, 7.19.4-r0, 7.19.5-r0 |
Timeline
- Nov 7, 2025 CVE Published
- Dec 3, 2025 CVE Updated
- Apr 30, 2026 Distribution Patch