CVE-2025-69412
published 2026-01-01CVE-2025-69412: KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing…
PriorityP416low3.4CVSS 3.1
AVAACHPRNUINSCCNILAN
EPSS
0.25%
16.7th percentile
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | kf5-messagelib | < messagelib 4:25.08.3-3 (forky) | messagelib 4:25.08.3-3 (forky) |
| debian | messagelib | < messagelib 4:25.08.3-3 (forky) | messagelib 4:25.08.3-3 (forky) |
| kde | messagelib | < 25.11.90 | 25.11.90 |
| kde | messagelib | >= 0 < 4:25.08.3-3 | 4:25.08.3-3 |
CVSS provenance
nvdv3.13.4LOWCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N
osv3.4LOW
vendor_debian3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-69412: kf5-messagelib - KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the ...
vendor_debian·2025·CVSS 3.4
CVE-2025-69412 [LOW] CVE-2025-69412: kf5-messagelib - KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the ...
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Scope: local
bookworm: open
bullseye: open
OSV
CVE-2025-69412: KDE messagelib before 25
osv·2026-01-01·CVSS 3.4
CVE-2025-69412 [LOW] CVE-2025-69412: KDE messagelib before 25
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
GHSA
GHSA-q5rr-6j45-r8gx: KDE messagelib before 25
ghsa_unreviewed·2026-01-01
CVE-2025-69412 [LOW] CWE-295 GHSA-q5rr-6j45-r8gx: KDE messagelib before 25
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [epel-8]
bugzilla·2026-01-01·CVSS 3.4
CVE-2025-69412 [LOW] CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [epel-8]
CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [epel-8]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
Bugzilla
CVE-2025-69412 messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [fedora-42]
bugzilla·2026-01-01·CVSS 3.4
CVE-2025-69412 [LOW] CVE-2025-69412 messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [fedora-42]
CVE-2025-69412 messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to c
Bugzilla
CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [epel-9]
bugzilla·2026-01-01·CVSS 3.4
CVE-2025-69412 [LOW] CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [epel-9]
CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This package has changed maintainer in Fedora. Reassigning to the new maintainer of this component.
Bugzilla
CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [fedora-42]
bugzilla·2026-01-01·CVSS 3.4
CVE-2025-69412 [LOW] CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [fedora-42]
CVE-2025-69412 kf5-messagelib: messagelib: Spoofing of threat data due to ignored SSL errors [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy
Wiz
CVE-2025-69412 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.4
CVE-2025-69412 [LOW] CVE-2025-69412 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69412 :
Linux Debian vulnerability analysis and mitigation
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Source : NVD
## 3.4
Score
Published January 1, 2026
Severity LOW
CNA Score 3.4
Affected Technologies
Linux Debian
Linux Alpine
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
kf5-messagelib
messagelib
Sources
NVD
Alpine 3.23 Severity LOW Has Fix Added at: Jan 11, 2026
Debian 11, 12, 13
2026-01-01
Published