VDB
DEBIAN-CVE-2025-15224
DEBIAN-CVE-2025-15224
PUBLISHED
CVSS 3.0999999046325684 LOW
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
Risk Scores
CVSS 3.1
3.0999999046325684
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | curl | 8.17.0-2, 8.16.0~rc3-1, 8.16.0~rc2-1 |
| Debian:13 | curl | 8.20.0~rc2-1, 8.20.0~rc1-1+exp3, 8.20.0~rc1-1+exp2 |
| Debian:11 | curl | 8.4.0-2, 8.10.0-1, 8.14.0-1 |
| Debian:12 | curl | 8.10.0-2, 8.10.1-1, 8.10.1-1 |
Exploit Intelligence
- CVE-2025-15224.json (github-poc)
- vote.json (github-poc)
- 2026.xml (github-poc)
- 2026.xml (github-poc)
- glcve_test.go (github-poc)
Timeline
- Jan 8, 2026 CVE Published
- Apr 28, 2026 CVE Updated