Certificate Verification Vulnerability in libcurl Affecting QUIC Connections
CVE-2025-4947

6.5MEDIUM

Key Information:

Vendor

Curl

Status
Vendor
CVE Published:
28 May 2025

What is CVE-2025-4947?

A vulnerability in libcurl allows for certificate verification to be skipped when QUIC connections are made to a host specified as an IP address. This oversight can lead to potential man-in-the-middle attacks, as the system fails to authenticate the identity of the server, making it susceptible to impersonation and data interception.

Affected Version(s)

curl 8.13.0

curl 8.12.1

curl 8.12.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hiroki Kurosawa
Stefan Eissing
.