CVE Explorer
CVE-2026-9547
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without warning and risk
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"lessThanOrEqual":"8.20.0","status":"affected","version":"8.20.0","versionType":"semver"},{"lessThanOrEqual":"8.19.0","status":"affected","version":"8.19.0","versionType":"semver"},{"lessThanOrEqual":"8.18.0","status":"affected","version":"8.18.0","versionType":"semver"},{"lessThanOrEqual":"8.17.0","status":"affected","version":"8.17.0","versionType":"semver"},{"lessThanOrEqual":"8.16.0","status":"affected","version":"8.16.0","versionType":"semver"},{"lessThanOrEqual":"8.15.0","status":"affected","version":"8.15.0","ve…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:e9d2f1cc8fe09380e8cd304ddeac51a52630658a5f143e0ea5139b4c29619436 · sha256:0f7ffe83d3b17ab2… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:e9d2f1cc8fe09380e8cd304ddeac51a52630658a5f143e0ea5139b4c29619436 · sha256:0f7ffe83d3b17ab2… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"description":"CWE-297 Improper Validation of Certificate with Host Mismatch","lang":"en"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:e9d2f1cc8fe09380e8cd304ddeac51a52630658a5f143e0ea5139b4c29619436 · sha256:0f7ffe83d3b17ab2… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"name":"www","url":"https://curl.se/docs/CVE-2026-9547.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e9d2f1cc8fe09380e8cd304ddeac51a52630658a5f143e0ea5139b4c29619436 · sha256:0f7ffe83d3b17ab2… · /containers/cna/references/1
{"name":"json","url":"https://curl.se/docs/CVE-2026-9547.json"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e9d2f1cc8fe09380e8cd304ddeac51a52630658a5f143e0ea5139b4c29619436 · sha256:0f7ffe83d3b17ab2… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://hackerone.com/reports/3751712"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e9d2f1cc8fe09380e8cd304ddeac51a52630658a5f143e0ea5139b4c29619436 · sha256:0f7ffe83d3b17ab2… · /containers/adp/0/references/0
{"name":"issue","url":"https://hackerone.com/reports/3751712"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:e9d2f1cc8fe09380e8cd304ddeac51a52630658a5f143e0ea5139b4c29619436 · sha256:0f7ffe83d3b17ab2… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.