TROYANOSYVIRUS
Retour aux CVEs

CVE-2025-14017

MEDIUM
6.3

Description

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.

Details CVE

Score CVSS v3.16.3
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Vecteur d'attaqueLOCAL
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie1/8/2026
Derniere modification1/27/2026
Sourcenvd
Observations honeypot0

Produits affectes

haxx:curl

References

https://curl.se/docs/CVE-2025-14017.html(2499f714-1537-4658-8207-48ae4bb9eae9)
https://curl.se/docs/CVE-2025-14017.json(2499f714-1537-4658-8207-48ae4bb9eae9)
http://www.openwall.com/lists/oss-security/2026/01/07/3(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.