Vulnerability in libcurl's Public Key Verification for QUIC Connections
CVE-2025-13034
What is CVE-2025-13034?
A vulnerability in libcurl arises from a failure to properly verify the public key of a server certificate when using the CURLOPT_PINNEDPUBLICKEY option or the --pinnedpubkey curl command. This issue is particularly notable when connections are made using QUIC with ngtcp2 linked to GnuTLS, and when users explicitly disable standard certificate verification. By skipping this essential verification step, libcurl allows the possibility of connecting to an impostor server without detection, raising significant security concerns.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
curl 8.17.0
curl 8.16.0
curl 8.15.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
