{"id":"AZL-91812","summary":"CVE-2026-12064 affecting package curl for versions less than 8.11.1-10","details":"When a user invokes curl using a schemeless URL combined with\n`--proto-default` sftp (or scp), a disconnect occurs between the tool layer\nand libcurl. The tool layer incorrectly infers the URL scheme, which\nerroneously bypasses the initialization of critical SSH security options like\nCURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the\nlibcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes\nthe connection via SFTP/SCP as specified. Because the tool layer skipped the\nsecurity configuration, these SSH host verification options are silently\nomitted, causing curl to connect to an unverified SSH remote host without\nthrowing an error.","modified":"2026-09-09T05:29:25Z","published":"2026-07-03T07:16:24Z","upstream":["CVE-2026-12064"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12064"}],"affected":[{"package":{"name":"curl","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/curl"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.11.1-10"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91812.json"}}],"schema_version":"1.9.0"}