CVE-2025-4947Improper Certificate Validation in Curl

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 77.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 28

Description

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 3.9 | Impact: 2.5

Affected Packages3 packages

NVDhaxx/curl8.8.08.14.0
Debianhaxx/curl< 8.14.0-1+1
CVEListV5curl/curl8.13.08.13.0+9

Patches

🔴Vulnerability Details

3
GHSA
GHSA-ppfq-jg49-mqj4: libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL2025-05-28
CVEList
QUIC certificate check skip with wolfSSL2025-05-28
OSV
CVE-2025-4947: libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL2025-05-28

📋Vendor Advisories

3
Red Hat
libcurl: curl: QUIC certificate check skip with wolfSSL2025-05-28
Microsoft
QUIC certificate check skip with wolfSSL2025-05-13
Debian
CVE-2025-4947: curl - libcurl accidentally skips the certificate verification for QUIC connections whe...2025

💬Community

1
HackerOne
CVE-2025-4947: QUIC certificate check skip with wolfSSL2025-05-28
CVE-2025-4947 — Improper Certificate Validation in Curl | cvebase