CVE-2025-4947
EUVD-2025-1630328.05.2025, 07:15
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| haxx | curl | 8.8.0 ≤ 𝑥 < 8.14.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| curl | curl | 𝑥 ≤ 8.13.0 | CNA |
| curl | curl | 𝑥 ≤ 8.12.1 | CNA |
| curl | curl | 𝑥 ≤ 8.12.0 | CNA |
| curl | curl | 𝑥 ≤ 8.11.1 | CNA |
| curl | curl | 𝑥 ≤ 8.11.0 | CNA |
| curl | curl | 𝑥 ≤ 8.10.1 | CNA |
| curl | curl | 𝑥 ≤ 8.10.0 | CNA |
| curl | curl | 𝑥 ≤ 8.9.1 | CNA |
| curl | curl | 𝑥 ≤ 8.9.0 | CNA |
| curl | curl | 𝑥 ≤ 8.8.0 | CNA |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| curl |
| ||||||||||||
| libcurl-devel |
| ||||||||||||
| libcurl4 |
| ||||||||||||
| libcurl4-32bit |
|
Common Weakness Enumeration