Medium severity6.5NVD Advisory· Published May 28, 2025· Updated Jun 17, 2026
CVE-2025-4947
CVE-2025-4947
Description
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords5 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/curl&distro=SUSE%20Linux%20Micro%206.1
< 8.14.1-150600.4.28.1+ 4 more
- (no CPE)range: < 8.14.1-150600.4.28.1
- (no CPE)range: < 8.14.0-1.1
- (no CPE)range: < 8.14.1-150600.4.28.1
- (no CPE)range: < 8.14.1-150600.4.28.1
- (no CPE)range: < 8.14.1-slfo.1.1_1.1
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2025/05/28/4nvdMailing ListPatchThird Party Advisory
- curl.se/docs/CVE-2025-4947.htmlnvdPatchVendor Advisory
- hackerone.com/reports/3150884nvdExploitIssue TrackingPatch
- curl.se/docs/CVE-2025-4947.jsonnvdVendor Advisory
News mentions
0No linked articles in our index yet.