CVE-2026-12064
ADVISORY - nistSummary
When a user invokes curl using a schemeless URL combined with
--proto-default sftp (or scp), a disconnect occurs between the tool layer
and libcurl. The tool layer incorrectly infers the URL scheme, which
erroneously bypasses the initialization of critical SSH security options like
CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the
libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes
the connection via SFTP/SCP as specified. Because the tool layer skipped the
security configuration, these SSH host verification options are silently
omitted, causing curl to connect to an unverified SSH remote host without
throwing an error.
Common Weakness Enumeration (CWE)
Improper Certificate Validation
NIST
3.9
CVSS SCORE
7.5highAlpine
-
Debian
-
CVSS SCORE
N/AlowUbuntu
-
CVSS SCORE
N/AlowChainguard
CGA-g64q-pg37-hx53
-
minimos
MINI-57vg-25pp-5hq8
-
minimos
MINI-7qgx-477r-f5v8
-