CVE-2025-15224: libssh key passphrase bypass without agent set
Published Jan 7, 2026
·Updated
When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.
Affected Software
3 affected components
curl
haxx curl>=7.58.0<8.18.0
IBM API Connect<=V10.0.8.0 - V10.0.8.9
Remediation
Patch Available
Patch Available
Event History
Jan 8, 2026
CVE Published
via MITRE·10:08 AM
Data Sourced
via MITRE·10:08 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-15224?
CVE-2025-15224 is rated as a medium severity vulnerability.
2
How do I fix CVE-2025-15224?
To fix CVE-2025-15224, update your curl application to the latest version that has addressed this vulnerability.
3
What impact does CVE-2025-15224 have on SSH-based transfers?
CVE-2025-15224 can lead to incorrect public key authentication process during SSH-based transfers using SCP or SFTP.
4
Which versions of curl are affected by CVE-2025-15224?
CVE-2025-15224 affects specific versions of curl that have not implemented the fix for this vulnerability.
5
Can CVE-2025-15224 be exploited remotely?
CVE-2025-15224 does not appear to allow for remote exploitation but affects the authentication method when used locally.