cbcvebase.
CVE-2025-14819
published 2026-01-08

CVE-2025-14819: When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA…

PriorityP428medium5.3CVSS 3.1
AVNACHPRNUIRSUCHINAN
EPSS
0.74%
53.1th percentile
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——
curlcurl——

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.