CVE-2025-14017

Aliases:DEBIAN-CVE-2025-14017ALPINE-CVE-2025-14017CGA-g429-4w8r-cfx6
Modified
Published: 08 Jan 2026, 10:07
Last modified:15 Sept 2026, 06:02

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.12% LOW
0% probability +0.11%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Jan 2026, 10:07
Published
Vulnerability first disclosed
15 Sept 2026, 06:02
Last Modified
Vulnerability information updated

Description

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.

CVSS Metrics

  • v3.1MEDIUMScore: 6.3CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.12% Percentile: 2%

Techniques & Countermeasures

  • CWE-567Unsynchronized Access to Shared Data in a Multithreaded Context

    The product does not properly synchronize shared data, such as static variables across threads, which can lead to undefined behavior and unpredictable data changes.

Affected Systems

  • alpinecurl

    ≥ 7.17.0, < 8.19.0-r0 | ≥ 7.17.0, < 8.18.0-r0 | ≥ 7.17.0, < 8.18.0-r0

  • chainguardlibcurl4

    all

  • wolfilibcurl4

    all

  • curlcurl

    8.17.0 | 8.16.0 | 8.15.0 | 8.14.1 | 8.14.0 | 8.13.0 | 8.12.1 | 8.12.0 | 8.11.1 | 8.11.0 | 8.10.1 | 8.10.0 | 8.9.1 | 8.9.0 | 8.8.0 | 8.7.1 | 8.7.0 | 8.6.0 | 8.5.0 | 8.4.0 | 8.3.0 | 8.2.1 | 8.2.0 | 8.1.2 | 8.1.1 | 8.1.0 | 8.0.1 | 8.0.0 | 7.88.1 | 7.88.0 | 7.87.0 | 7.86.0 | 7.85.0 | 7.84.0 | 7.83.1 | 7.83.0 | 7.82.0 | 7.81.0 | 7.80.0 | 7.79.1 | 7.79.0 | 7.78.0 | 7.77.0 | 7.76.1 | 7.76.0 | 7.75.0 | 7.74.0 | 7.73.0 | 7.72.0 | 7.71.1 | 7.71.0 | 7.70.0 | 7.69.1 | 7.69.0 | 7.68.0 | 7.67.0 | 7.66.0 | 7.65.3 | 7.65.2 | 7.65.1 | 7.65.0 | 7.64.1 | 7.64.0 | 7.63.0 | 7.62.0 | 7.61.1 | 7.61.0 | 7.60.0 | 7.59.0 | 7.58.0 | 7.57.0 | 7.56.1 | 7.56.0 | 7.55.1 | 7.55.0 | 7.54.1 | 7.54.0 | 7.53.1 | 7.53.0 | 7.52.1 | 7.52.0 | 7.51.0 | 7.50.3 | 7.50.2 | 7.50.1 | 7.50.0 | 7.49.1 | 7.49.0 | 7.48.0 | 7.47.1 | 7.47.0 | 7.46.0 | 7.45.0 | 7.44.0 | 7.43.0 | 7.42.1 | 7.42.0 | 7.41.0 | 7.40.0 | 7.39.0 | 7.38.0 | 7.37.1 | 7.37.0 | 7.36.0 | 7.35.0 | 7.34.0 | 7.33.0 | 7.32.0 | 7.31.0 | 7.30.0 | 7.29.0 | 7.28.1 | 7.28.0 | 7.27.0 | 7.26.0 | 7.25.0 | 7.24.0 | 7.23.1 | 7.23.0 | 7.22.0 | 7.21.7 | 7.21.6 | 7.21.5 | 7.21.4 | 7.21.3 | 7.21.2 | 7.21.1 | 7.21.0 | 7.20.1 | 7.20.0 | 7.19.7 | 7.19.6 | 7.19.5 | 7.19.4 | 7.19.3 | 7.19.2 | 7.19.1 | 7.19.0 | 7.18.2 | 7.18.1 | 7.18.0 | 7.17.1 | 7.17.0 | ≥ 7.17.0, < 8.14.2 | ≥ 8.15.0, < 8.16.1 | ≥ 8.17.0, < 8.18.0 | ≥ ccba0d10b6baf5c73cae8cf4fb3f29f0f55c5a34, < 39d1976b7f709a516e3243338ebc0443bdd8d56d | 8.17.0 | 8.16.0 | 8.15.0 | 8.14.1 | 8.14.0 | 8.13.0 | 8.12.1 | 8.12.0 | 8.11.1 | 8.11.0 | 8.10.1 | 8.10.0 | 8.9.1 | 8.9.0 | 8.8.0 | 8.7.1 | 8.7.0 | 8.6.0 | 8.5.0 | 8.4.0 | 8.3.0 | 8.2.1 | 8.2.0 | 8.1.2 | 8.1.1 | 8.1.0 | 8.0.1 | 8.0.0 | 7.88.1 | 7.88.0 | 7.87.0 | 7.86.0 | 7.85.0 | 7.84.0 | 7.83.1 | 7.83.0 | 7.82.0 | 7.81.0 | 7.80.0 | 7.79.1 | 7.79.0 | 7.78.0 | 7.77.0 | 7.76.1 | 7.76.0 | 7.75.0 | 7.74.0 | 7.73.0 | 7.72.0 | 7.71.1 | 7.71.0 | 7.70.0 | 7.69.1 | 7.69.0 | 7.68.0 | 7.67.0 | 7.66.0 | 7.65.3 | 7.65.2 | 7.65.1 | 7.65.0 | 7.64.1 | 7.64.0 | 7.63.0 | 7.62.0 | 7.61.1 | 7.61.0 | 7.60.0 | 7.59.0 | 7.58.0 | 7.57.0 | 7.56.1 | 7.56.0 | 7.55.1 | 7.55.0 | 7.54.1 | 7.54.0 | 7.53.1 | 7.53.0 | 7.52.1 | 7.52.0 | 7.51.0 | 7.50.3 | 7.50.2 | 7.50.1 | 7.50.0 | 7.49.1 | 7.49.0 | 7.48.0 | 7.47.1 | 7.47.0 | 7.46.0 | 7.45.0 | 7.44.0 | 7.43.0 | 7.42.1 | 7.42.0 | 7.41.0 | 7.40.0 | 7.39.0 | 7.38.0 | 7.37.1 | 7.37.0 | 7.36.0 | 7.35.0 | 7.34.0 | 7.33.0 | 7.32.0 | 7.31.0 | 7.30.0 | 7.29.0 | 7.28.1 | 7.28.0 | 7.27.0 | 7.26.0 | 7.25.0 | 7.24.0 | 7.23.1 | 7.23.0 | 7.22.0 | 7.21.7 | 7.21.6 | 7.21.5 | 7.21.4 | 7.21.3 | 7.21.2 | 7.21.1 | 7.21.0 | 7.20.1 | 7.20.0 | 7.19.7 | 7.19.6 | 7.19.5 | 7.19.4 | 7.19.3 | 7.19.2 | 7.19.1 | 7.19.0 | 7.18.2 | 7.18.1 | 7.18.0 | 7.17.1 | 7.17.0

  • debiancurl

    all | all | all | < 8.18.0~rc2-1

  • haxxcurl

    ≥ 7.17.0, < 8.18.0

References (5)