CVE-2025-15224: libssh key passphrase bypass without agent set
Published Jan 7, 2026
·Updated
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
Affected Software
4 affected components
curl
haxx curl>=7.58.0<8.18.0
IBM MQ Operator<=SC2: v3.2.0 - v3.2.23
CD: v3.3.0, v3.4.0, v3.4.1, v3.5.0, v3.5.1 - v3.5.3, v3.6.0 - v3.6.4, v3.7.0 - v3.7.2, v3.8.0, v3.8.1, v3.9.0, v3.9.1
LTS: v2.0.0 - 2.0.29
IBM supplied MQ Advanced container images<=SC2: 9.4.0.6-r1, 9.4.0.6-r2, 9.4.0.7-r1, 9.4.0.10-r1, 9.4.0.10-r2, 9.4.0.11-r1, 9.4.0.11-r2, 9.4.0.11-r3, 9.4.0.12-r1, 9.4.0.15-r1 - 9.4.0.15-r4, 9.4.0.16-r1, 9.4.0.16-r2, 9.4.0.17-r1, 9.4.0.17-r2, 9.4.0.20-r1CD: 9.4.1.0-r1, 9.4.1.0-r2, 9.4.1.1-r1, 9.4.2.0-r1, 9.4.2.0-r2, 9.4.2.1-r1, 9.4.2.1-r2, 9.4.3.0-r1, 9.4.3.0-r2, 9.4.3.1-r1 - 9.4.3.1-r3, 9.4.4.0-r1 - 9.4.4.0-r4, 9.4.4.1-r1, 9.4.5.0-r1, 9.4.5.0-r2LTS: 9.3.0.0-r1, 9.3.0.0-r2, 9.3.0.0-r3, 9.3.0.1-r1, 9.3.0.1-r2, 9.3.0.1-r3, 9.3.0.1-r4, 9.3.0.3-r1, 9.3.0.4-r1, 9.3.0.4-r2, 9.3.0.5-r1, 9.3.0.5-r2, 9.3.0.5-r3, 9.3.0.6-r1, 9.3.0.10-r1, 9.3.0.10-r2, 9.3.0.11-r1,9.3.0.11-r2, 9.3.0.15-r1, 9.3.0.16-r1, 9.3.0.16-r2, 9.3.0.17-r1, 9.3.0.17-r2, 9.3.0.17-r3, 9.3.0.20-r1, 9.3.0.20-r2, 9.3.0.21-r1, 9.3.0.21-r2, 9.3.0.21-r3, 9.3.0.25-r1, 9.4.0.0-r1, 9.4.0.0-r2, 9.4.0.0-r3, 9.4.0.5-r1, 9.4.0.5-r2
Remediation
Patch Available
Patch Available
Event History
Jan 8, 2026
CVE Published
via MITRE·10:08 AM
Data Sourced
via MITRE·10:08 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 15, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15224?
CVE-2025-15224 is rated as a medium severity vulnerability.
2
How do I fix CVE-2025-15224?
To fix CVE-2025-15224, update your curl application to the latest version that has addressed this vulnerability.
3
What impact does CVE-2025-15224 have on SSH-based transfers?
CVE-2025-15224 can lead to incorrect public key authentication process during SSH-based transfers using SCP or SFTP.
4
Which versions of curl are affected by CVE-2025-15224?
CVE-2025-15224 affects specific versions of curl that have not implemented the fix for this vulnerability.
5
Can CVE-2025-15224 be exploited remotely?
CVE-2025-15224 does not appear to allow for remote exploitation but affects the authentication method when used locally.