CVE-2025-15079Patch(haxx / curl)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haxx curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts *not present* in the specified file if they were added as recognized in the libssh *global* known_hosts file.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-297

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-19); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-19: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Patch / Workaround · 2026-03-13: 102-1903-1303-1403-15
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-03-131
Patch1
2026-03-141
General1
2026-03-151
Patch1
Full discourse4 posts
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-15079 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/412 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet notes that CVE‑2025‑15079 has been removed from the latest AWS Lambda base images, indicating the issue has been addressed, though no specific patch details are provided.

    00000139
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-15079 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/412 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post reports that CVE-2025-15079 is no longer present in the latest AWS Lambda base images, implying remediation, but provides no further technical or exploitation details.

    00000137
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-15079 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/412 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS has mitigated CVE‑2025‑15079 by removing it from the latest Lambda base images; no PoC, exploit tool, or active exploitation claims are presented.

    00000123
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2025-15079 impacts curl-minimal in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/412 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The tweet announces the detection of CVE‑2025‑15079 in AWS Lambda's curl‑minimal images, providing links to an issue and a monitoring site, but offers no exploit, patch, or technical details.

    0000036
    30 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more