Summary
libcurl’s connection-pool matching did not compare the SSH public/private-key configuration for a new request with the context of an existing connection. When two SSH or SFTP requests targeted the same destination with different key settings, the second could silently reuse the first request’s authenticated channel and operate as the wrong identity.
The public disclosure points to the upstream repair that restored SSH configuration matching. It is counted without a CVE because the accepted, fixed report is public and sufficiently specific; the AI role remains an operator claim.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.