rpm package
suse/curl&distro=SUSE Manager Proxy LTS 4.3
pkg:rpm/suse/curl&distro=SUSE%20Manager%20Proxy%20LTS%204.3
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2025-9086 | Hig | 7.5 | < 8.14.1-150400.5.69.1 | 8.14.1-150400.5.69.1 | Sep 12, 2025 | 1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path | |
| CVE-2025-10148 | Med | 5.3 | < 8.14.1-150400.5.69.1 | 8.14.1-150400.5.69.1 | Sep 12, 2025 | curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traf |
- affected < 8.14.1-150400.5.69.1fixed 8.14.1-150400.5.69.1
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name is set - but with just a slash as path
- affected < 8.14.1-150400.5.69.1fixed 8.14.1-150400.5.69.1
curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traf