CVE-2025-14819

Analyzed
Published: 08 Jan 2026, 10:07
Last modified:08 Jan 2026, 15:02

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.68% LOW
1% probability +0.63%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 Jan 2026, 10:07
Published
Vulnerability first disclosed
08 Jan 2026, 15:02
Last Modified
Vulnerability information updated

Description

When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.68% Percentile: 48%

Techniques & Countermeasures

  • CWE-295Improper Certificate Validation

    The product does not validate, or incorrectly validates, a certificate.

Affected Systems

  • curlcurl

    8.17.0 | 8.16.0 | 8.15.0 | 8.14.1 | 8.14.0 | 8.13.0 | 8.12.1 | 8.12.0 | 8.11.1 | 8.11.0 | 8.10.1 | 8.10.0 | 8.9.1 | 8.9.0 | 8.8.0 | 8.7.1 | 8.7.0 | 8.6.0 | 8.5.0 | 8.4.0 | 8.3.0 | 8.2.1 | 8.2.0 | 8.1.2 | 8.1.1 | 8.1.0 | 8.0.1 | 8.0.0 | 7.88.1 | 7.88.0 | 7.87.0

  • haxxcurl

    ≥ 7.87.0, < 8.18.0

References (3)