Sploitus

CVE-2026-9547

No indexed exploits for CVE-2026-9547 yet

When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

Affected products
Ibm Aix, Linuxmint, Rocky Linux, Libcurl
Haxx Curl
< 8.21.0
CVSS 3.1
7.4 HIGH
EPSS
0.3% (25th percentile)
NVD status
Analyzed
Published
2026-07-03
CVE-2026-9547 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-9547 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-9547 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.