Denial of Service in libcurl's WebSocket Implementation
CVE-2025-5399
Currently unrated
What is CVE-2025-5399?
A vulnerability in libcurl's WebSocket handling allows a remote server to deliver a specially crafted packet, which can cause applications utilizing libcurl to enter an infinite busy-loop. This condition prevents the application from terminating or recovering without forcibly terminating the process. Such an occurrence may be exploited to launch Denial of Service attacks against libcurl-dependent applications.
Affected Version(s)
curl 8.14.0
curl 8.13.0