[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2025:03198-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-01T00:21:03.480Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":28,"duplicates":29,"related":30,"reserved_at":9,"published_at":38,"modified_at":39,"state":9,"summary":40,"references_raw":42,"kevs":116,"epss":9,"epss_history":117,"metrics":118,"affected":119},"SUSE-SU-2025:03198-1","Security update for curl\n\nThis update for curl fixes the following issues:\n\nUpdate to version 8.14.1 (jsc#PED-13055, jsc#PED-13056).    \n    \nSecurity issues fixed:\n\n- CVE-2025-0665: eventfd double close can cause libcurl to act unreliably (bsc#1236589).\n- CVE-2025-4947: QUIC certificate check is skipped with wolfSSL allows for MITM attacks (bsc#1243397).\n- CVE-2025-5025: no QUIC certificate pinning with wolfSSL can lead to connections to impostor servers that are not\n  easily noticed (bsc#1243706).\n- CVE-2025-5399: bug in websocket code can cause libcurl to get trapped in an endless busy-loop when processing\n  specially crafted packets (bsc#1243933).\n- CVE-2024-6874: punycode conversions to/from IDN can leak stack content when libcurl is built to use the macidn IDN\n  backend (bsc#1228260).\n- CVE-2025-9086: bug in patch comparison logic when processing cookies can lead to out-of-bounds read in heap buffer\n  (bsc#1249191).\n- CVE-2025-10148: predictable websocket mask can lead to proxy cache poisoning by malicious server (bsc#1249348).\n\nOther issues fixed:\n    \n- Fix wrong return code when --retry is used (bsc#1249367).\n  * tool_operate: fix return code when --retry is used but not triggered [b42776b]\n    \n- Fix the --ftp-pasv option in curl v8.14.1 (bsc#1246197).\n  * tool_getparam: fix --ftp-pasv [5f805ee]\n\n- Fixed with version 8.14.1:\n  * TLS: add CURLOPT_SSL_SIGNATURE_ALGORITHMS and --sigalgs.\n  * websocket: add option to disable auto-pong reply.\n  * huge number of bugfixes.\n\n  Please see https://curl.se/ch/ for full changelogs.\n",null,[],[],[],[14,16,18,20,22,24,26],{"_key":15},"CVE-2024-6874",{"_key":17},"CVE-2025-0665",{"_key":19},"CVE-2025-10148",{"_key":21},"CVE-2025-4947",{"_key":23},"CVE-2025-5025",{"_key":25},"CVE-2025-5399",{"_key":27},"CVE-2025-9086",[],[],[31,32,33,34,35,36,37],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},"2025-09-12T12:15:10Z","2026-03-23T04:50:28.709496Z",{"cisa_kev":41,"cisa_ransomware":41,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[43,50,55,59,63,67,71,75,79,83,87,92,96,100,104,108,112],{"url":44,"sources":45,"tags":48},"https://www.suse.com/support/update/announcement/2025/suse-su-202503198-1/",[46,47],"osv_suse","osv_opensuse",[49],"Advisory",{"url":51,"sources":52,"tags":53},"https://bugzilla.suse.com/1228260",[46,47],[54],"REPORT",{"url":56,"sources":57,"tags":58},"https://bugzilla.suse.com/1236589",[46,47],[54],{"url":60,"sources":61,"tags":62},"https://bugzilla.suse.com/1243397",[46,47],[54],{"url":64,"sources":65,"tags":66},"https://bugzilla.suse.com/1243706",[46,47],[54],{"url":68,"sources":69,"tags":70},"https://bugzilla.suse.com/1243933",[46,47],[54],{"url":72,"sources":73,"tags":74},"https://bugzilla.suse.com/1246197",[46,47],[54],{"url":76,"sources":77,"tags":78},"https://bugzilla.suse.com/1249191",[46,47],[54],{"url":80,"sources":81,"tags":82},"https://bugzilla.suse.com/1249348",[46,47],[54],{"url":84,"sources":85,"tags":86},"https://bugzilla.suse.com/1249367",[46,47],[54],{"url":88,"sources":89,"tags":90},"https://www.suse.com/security/cve/CVE-2024-6874",[46,47],[91],"WEB",{"url":93,"sources":94,"tags":95},"https://www.suse.com/security/cve/CVE-2025-0665",[46,47],[91],{"url":97,"sources":98,"tags":99},"https://www.suse.com/security/cve/CVE-2025-10148",[46,47],[91],{"url":101,"sources":102,"tags":103},"https://www.suse.com/security/cve/CVE-2025-4947",[46,47],[91],{"url":105,"sources":106,"tags":107},"https://www.suse.com/security/cve/CVE-2025-5025",[46,47],[91],{"url":109,"sources":110,"tags":111},"https://www.suse.com/security/cve/CVE-2025-5399",[46,47],[91],{"url":113,"sources":114,"tags":115},"https://www.suse.com/security/cve/CVE-2025-9086",[46,47],[91],[],[],[],[120,133,139],{"ecosystem":121,"name":122,"vendor":123,"product":124,"cpe_part":9,"purl_type":125,"purl_namespace":123,"purl_name":124,"source":9,"versions":126},"openSUSE","curl","opensuse","curl&distro=openSUSE Leap 15.6","rpm",[127],{"version":128,"is_range":129,"range_type":130,"version_start":9,"version_start_type":9,"version_end":131,"version_end_type":132,"fixed_in":9},"lt8_14_1_150600_4_28_1",true,"ecosystem","8.14.1-150600.4.28.1","excluding",{"ecosystem":134,"name":122,"vendor":135,"product":136,"cpe_part":9,"purl_type":125,"purl_namespace":135,"purl_name":136,"source":9,"versions":137},"SUSE Linux Enterprise","suse","curl&distro=SUSE Linux Enterprise Module for Basesystem 15 SP6",[138],{"version":128,"is_range":129,"range_type":130,"version_start":9,"version_start_type":9,"version_end":131,"version_end_type":132,"fixed_in":9},{"ecosystem":134,"name":122,"vendor":135,"product":140,"cpe_part":9,"purl_type":125,"purl_namespace":135,"purl_name":140,"source":9,"versions":141},"curl&distro=SUSE Linux Enterprise Module for Basesystem 15 SP7",[142],{"version":128,"is_range":129,"range_type":130,"version_start":9,"version_start_type":9,"version_end":131,"version_end_type":132,"fixed_in":9}]