PT-2026-51756 · Git · Curl

Published

2026-06-24

·

Updated

2026-06-24

·

CVE-2026-9547

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
When a libcurl-based application performs transfers via SCP:// or SFTP:// and utilizes the CURLOPT SSH KEYFUNCTION callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the known hosts file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9547

Affected Products

Curl