VYPR
High severity7.5NVD Advisory· Published Jun 7, 2025· Updated Jun 17, 2026

CVE-2025-5399

CVE-2025-5399

Description

Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop.

There is no other way for the application to escape or exit this loop other than killing the thread/process.

This might be used to DoS libcurl-using application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

25

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.