← Back

CVE-2025-14017

nvd nist
Published: Jan 8, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.3
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Exploitability: 1.0 / Impact: 5.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.

Affected (1)

Products: Haxx: Curl
1 product
Curl
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 7.17.0 to 8.18.0

References (3)

Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Vendor Advisory
Source: 2499f714-1537-4658-8207-48ae4bb9eae9
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory

Timeline

No history available yet.