CVE-2025-15224

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
08/01/2026
Last modified:
20/01/2026

Description

When doing SSH-based transfers using either SCP or SFTP, and asked to do<br /> public key authentication, curl would wrongly still ask and authenticate using<br /> a locally running SSH agent.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* 7.58.0 (including) 8.18.0 (excluding)