Bug 2496758 (CVE-2026-9547) - CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass
Summary: CVE-2026-9547 curl: curl: Man-in-the-middle attack via SSH host key bypass
Keywords:
Status: NEW
Alias: CVE-2026-9547
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2497409 2497411 2497410
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-03 07:01 UTC by OSIDB Bzimport
Modified: 2026-08-17 05:43 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:55439 0 None None None 2026-08-17 05:43:53 UTC
Red Hat Product Errata RHSA-2026:55450 0 None None None 2026-08-17 04:40:21 UTC

Description OSIDB Bzimport 2026-07-03 07:01:34 UTC
When a libcurl-based application performs transfers via `SCP://` or `SFTP://`
and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an
untrusted server. This vulnerability occurs when a server presents a host key
type that does not match the specific key type already recorded for that host
in the `known_hosts` file. Instead of rejecting the mismatch, the callback
mechanism fails to properly enforce the restriction, allowing the connection
to succeed without warning and risking a potential man-in-the-middle attack.

Comment 2 errata-xmlrpc 2026-08-17 04:40:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:55450 https://access.redhat.com/errata/RHSA-2026:55450

Comment 3 errata-xmlrpc 2026-08-17 05:43:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55439 https://access.redhat.com/errata/RHSA-2026:55439


Note You need to log in before you can comment on or make changes to this bug.