CVE-2025-13034

EUVD-2026-1572
When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`
with the curl tool, curl should check the public key of the server certificate
to verify the peer.

This check was skipped in a certain condition that would then make curl allow
the connection without performing the proper check, thus not noticing a
possible impostor. To skip this check, the connection had to be done with QUIC
with ngtcp2 built to use GnuTLS and the user had to explicitly disable the
standard certificate verification.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
curlCNA
5.9 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13.64%
Affected Products (NVD)
VendorProductVersion
haxxcurl
8.8.0 ≤
𝑥
< 8.18.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
curlcurl
8.8.0 ≤
𝑥
< 8.14.2
CNA
curlcurl
8.15.0 ≤
𝑥
< 8.16.1
CNA
curlcurl
8.17.0 ≤
𝑥
< 8.18.0
CNA
curlcurl
8.17.0
CNA
curlcurl
8.16.0
CNA
curlcurl
8.15.0
CNA
curlcurl
8.14.1
CNA
curlcurl
8.14.0
CNA
curlcurl
8.13.0
CNA
curlcurl
8.12.1
CNA
curlcurl
8.12.0
CNA
curlcurl
8.11.1
CNA
curlcurl
8.11.0
CNA
curlcurl
8.10.1
CNA
curlcurl
8.10.0
CNA
curlcurl
8.9.1
CNA
curlcurl
8.9.0
CNA
curlcurl
8.8.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
curl
bookworm
7.88.1-10+deb12u15
fixed
bookworm (security)
7.88.1-10+deb12u5
fixed
bullseye
not-affected
forky
8.22.0-1
fixed
sid
8.23.0~rc2-1
fixed
trixie
8.14.1-2+deb13u5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
curl
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
ignored
questing
Fixed 8.14.1-2ubuntu1.1
released
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
curl
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
curl-debuginfo
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
curl-debugsource
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
curl-minimal
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
curl-minimal-debuginfo
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
libcurl
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
libcurl-debuginfo
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
libcurl-devel
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
libcurl-minimal
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed
libcurl-minimal-debuginfo
Amazon Linux 2023
0:8.17.0-1.amzn2023.0.1
fixed