PT-2026-51756 · Git · Curl
Published
2026-06-24
·
Updated
2026-06-24
·
CVE-2026-9547
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
When a libcurl-based application performs transfers via
SCP:// or SFTP://
and utilizes the CURLOPT SSH KEYFUNCTION callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the known hosts file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without warning and risking a potential man-in-the-middle attack. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Curl