CVE-2025-5025
ADVISORY - nistSummary
libcurl supports pinning of the server certificate public key for HTTPS transfers. Due to an omission, this check is not performed when connecting with QUIC for HTTP/3, when the TLS backend is wolfSSL. Documentation says the option works with wolfSSL, failing to specify that it does not for QUIC and HTTP/3. Since pinning makes the transfer succeed if the pin is fine, users could unwittingly connect to an impostor server without noticing.
EPSS Score: 0.00018 (0.032)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Certificate Validation
Alpine
CREATED
UPDATED
ADVISORY IDCVE-2025-5025
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
| Package | Type | OS Name | OS Version | Affected Ranges | Fix Versions |
|---|---|---|---|---|---|
| alpine/curl | apk | alpine | 3.20 | <8.14.0-r0 | 8.14.0-r0 |
| alpine/curl | apk | alpine | 3.23 | <8.14.0-r0 | 8.14.0-r0 |
| alpine/curl | apk | alpine | edge | <8.14.0-r0 | 8.14.0-r0 |
| alpine/curl | apk | alpine | 3.22 | <8.14.0-r0 | 8.14.0-r0 |
| alpine/curl | apk | alpine | 3.19 | <8.14.0-r0 | 8.14.0-r0 |
| alpine/curl | apk | alpine | 3.21 | <8.14.0-r0 | 8.14.0-r0 |
Severity and metrics
No CVSS data available from this advisory.
NIST
CREATED
UPDATED
ADVISORY IDCVE-2025-5025
EXPLOITABILITY SCORE
2.2
EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
4.8mediumDebian
CREATED
UPDATED
ADVISORY IDCVE-2025-5025
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AlowUbuntu
CREATED
UPDATED
ADVISORY IDCVE-2025-5025
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
N/AmediumPhoton
CREATED
UPDATED
ADVISORY ID
CVE-2025-5025
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
CVSS SCORE
4.8mediumminimos
CREATED
UPDATED
ADVISORY ID
MINI-v932-4r2f-cqgq
EXPLOITABILITY SCORE
-
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-