CVE-2025-5025
EUVD-2025-1633228.05.2025, 07:15
libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since pinning makes the transfer succeed if the pin is fine, users could unwittingly connect to an impostor server without noticing.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| haxx | curl | 8.5.0 ≤ 𝑥 < 8.14.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| curl | curl | 𝑥 ≤ 8.13.0 | CNA |
| curl | curl | 𝑥 ≤ 8.12.1 | CNA |
| curl | curl | 𝑥 ≤ 8.12.0 | CNA |
| curl | curl | 𝑥 ≤ 8.11.1 | CNA |
| curl | curl | 𝑥 ≤ 8.11.0 | CNA |
| curl | curl | 𝑥 ≤ 8.10.1 | CNA |
| curl | curl | 𝑥 ≤ 8.10.0 | CNA |
| curl | curl | 𝑥 ≤ 8.9.1 | CNA |
| curl | curl | 𝑥 ≤ 8.9.0 | CNA |
| curl | curl | 𝑥 ≤ 8.8.0 | CNA |
| curl | curl | 𝑥 ≤ 8.7.1 | CNA |
| curl | curl | 𝑥 ≤ 8.7.0 | CNA |
| curl | curl | 𝑥 ≤ 8.6.0 | CNA |
| curl | curl | 𝑥 ≤ 8.5.0 | CNA |
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| curl |
| ||||||||||||
| libcurl-devel |
| ||||||||||||
| libcurl4 |
| ||||||||||||
| libcurl4-32bit |
|
Common Weakness Enumeration