Medium severity4.8NVD Advisory· Published May 28, 2025· Updated Jun 17, 2026
CVE-2025-5025
CVE-2025-5025
Description
libcurl supports *pinning* of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since pinning makes the transfer succeed if the pin is fine, users could unwittingly connect to an impostor server without noticing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords5 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/curl&distro=SUSE%20Linux%20Micro%206.1
< 8.14.1-150600.4.28.1+ 4 more
- (no CPE)range: < 8.14.1-150600.4.28.1
- (no CPE)range: < 8.14.0-1.1
- (no CPE)range: < 8.14.1-150600.4.28.1
- (no CPE)range: < 8.14.1-150600.4.28.1
- (no CPE)range: < 8.14.1-slfo.1.1_1.1
Patches
Vulnerability mechanics
References
4- hackerone.com/reports/3153497nvdExploitIssue TrackingThird Party Advisory
- www.openwall.com/lists/oss-security/2025/05/28/5nvdMailing ListThird Party Advisory
- curl.se/docs/CVE-2025-5025.htmlnvdVendor Advisory
- curl.se/docs/CVE-2025-5025.jsonnvdVendor Advisory
News mentions
0No linked articles in our index yet.