CVE-2025-66286

EUVD-2025-209565
An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the
WebPage::send-request signal handler to approve or reject all network requests. However, certain types of HTTP requests bypass this signal handler.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 14.06%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
webkit2gtk
bionic
ignored
focal
ignored
jammy
ignored
noble
deferred
questing
ignored
resolute
deferred
xenial
ignored
qtwebkit-opensource-src
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
questing
dne
resolute
dne
xenial
ignored
qtwebkit-source
bionic
ignored
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
ignored
webkitgtk
bionic
ignored
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
ignored
wpewebkit
focal
ignored
jammy
ignored
noble
dne
questing
dne
resolute
dne