<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE2-SA-2026-0007</id>
    <title>An update for curl is now available for HCE 2.0</title>
    <severity>Moderate</severity>
    <release>HCE 2.0</release>
    <issued date="2026-03-02 12:00:43"/>
    <updated date="2026-03-02 12:00:43"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2025-10966" id="CVE-2025-10966" title="CVE-2025-10966 Base Score: 4.3 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" type="cve"/>
    </references>
    <description>Security Fix(es):

curl_x27;s code for managing SSH connections when SFTP was done using the wolfSSH
powered backend was flawed and missed host verification mechanisms.

This prevents curl from detecting MITM attackers and more. (CVE-2025-10966)
</description>
    <pkglist>
      <collection short="HCE 2.0" package="curl">
        <name>HCE 2.0</name>
        <package arch="x86_64" name="curl" version="7.79.1" release="2.r36.hce2">
          <filename>curl-7.79.1-2.r36.hce2.x86_64.rpm</filename>
        </package>
        <package arch="noarch" name="curl-help" version="7.79.1" release="2.r36.hce2">
          <filename>curl-help-7.79.1-2.r36.hce2.noarch.rpm</filename>
        </package>
        <package arch="x86_64" name="libcurl" version="7.79.1" release="2.r36.hce2">
          <filename>libcurl-7.79.1-2.r36.hce2.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="libcurl-devel" version="7.79.1" release="2.r36.hce2">
          <filename>libcurl-devel-7.79.1-2.r36.hce2.x86_64.rpm</filename>
        </package>
        <package arch="aarch64" name="curl" version="7.79.1" release="2.r36.hce2">
          <filename>curl-7.79.1-2.r36.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="libcurl" version="7.79.1" release="2.r36.hce2">
          <filename>libcurl-7.79.1-2.r36.hce2.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="libcurl-devel" version="7.79.1" release="2.r36.hce2">
          <filename>libcurl-devel-7.79.1-2.r36.hce2.aarch64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
