CVE-2026-9547
When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
- Affected products
- Ibm Aix, Linuxmint, Rocky Linux, Libcurl
- Haxx Curl
- < 8.21.0
- CVSS 3.1
- 7.4 HIGH
- EPSS
- 0.3% (25th percentile)
- NVD status
- Analyzed
- Published
- 2026-07-03
No indexed exploits for CVE-2026-9547 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-9547 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.