Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-1222 High 7.4

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the ...

JLSEC Published
Modified
Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Packages
CURL_jll < 8.21.0+0
LibCURL_jll >= 7.70.0+0, < 8.21.0+0

When a libcurl-based application performs transfers via SCP:// or SFTP:// and utilizes the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the known_hosts file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

References