CVE-2025-15224General(haxx / curl)

LOWCVSS 3.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Patch: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-19); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-19: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 102-1903-1303-1403-15
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-03-131
General1
2026-03-141
Patch1
2026-03-151
General1
Full discourse4 posts
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-15224 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/413 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE‑2025‑15224 is no longer present in the latest AWS Lambda base images, indicating that the vulnerability has been resolved in those images.

    00000142
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-15224 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/413 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE‑2025‑15224 has been removed from the latest AWS Lambda base images, indicating the vulnerability is no longer present.

    00000143
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-15224 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/413 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog observed that CVE-2025-15224 is no longer present in the latest AWS Lambda base image scans, implying the vulnerability has been addressed or is absent in current images.

    00000128
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2025-15224 impacts curl-minimal in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/413 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new medium severity CVE-2025-15224 affecting curl‑minimal in 40 AWS Lambda base images has been detected, with references to a GitHub issue and a monitoring website. No exploitation details or patches are discussed.

    0000034
    30 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more