CVE-2025-5399

ADVISORY - nist

Summary

Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop.

There is no other way for the application to escape or exit this loop other than killing the thread/process.

This might be used to DoS libcurl-using application.

EPSS Score: 0.00043 (0.130)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Loop with Unreachable Exit Condition ('Infinite Loop')


Alpine

CREATED

UPDATED

ADVISORY IDCVE-2025-5399
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY
PackageTypeOS NameOS VersionAffected RangesFix Versions
alpine/curlapkalpine3.20<8.14.1-r08.14.1-r0
alpine/curlapkalpine3.20<8.14.1-r08.14.1-r0
alpine/curlapkalpineedge<8.14.1-r08.14.1-r0
alpine/curlapkalpineedge<=8.11.0-r2Not yet available
alpine/curlapkalpineedge<=8.11.1-r0Not yet available
alpine/curlapkalpineedge<=8.11.1-r1Not yet available
alpine/curlapkalpineedge<=8.12.0-r0Not yet available
alpine/curlapkalpineedge<=8.12.1-r0Not yet available
alpine/curlapkalpineedge<=8.12.1-r1Not yet available
alpine/curlapkalpineedge<=8.13.0-r0Not yet available
alpine/curlapkalpineedge<=8.13.0-r1Not yet available
alpine/curlapkalpineedge<=8.14.0-r0Not yet available
alpine/curlapkalpineedge<=8.14.0-r1Not yet available
alpine/curlapkalpineedge<=8.14.0-r2Not yet available
alpine/curlapkalpine3.19<8.14.1-r08.14.1-r0
alpine/curlapkalpine3.19<=8.11.1-r0Not yet available
alpine/curlapkalpine3.19<=8.11.1-r1Not yet available
alpine/curlapkalpine3.19<=8.12.0-r0Not yet available
alpine/curlapkalpine3.19<=8.12.1-r0Not yet available
alpine/curlapkalpine3.19<=8.9.1-r1Not yet available
alpine/curlapkalpine3.21<8.14.1-r08.14.1-r0
alpine/curlapkalpine3.19<8.14.1-r08.14.1-r0
alpine/curlapkalpineedge<8.14.1-r08.14.1-r0
alpine/curlapkalpine3.23<8.14.1-r08.14.1-r0
alpine/curlapkalpine3.20<=8.11.0-r2Not yet available
alpine/curlapkalpine3.20<=8.11.1-r0Not yet available
alpine/curlapkalpine3.20<=8.11.1-r1Not yet available
alpine/curlapkalpine3.20<=8.12.0-r0Not yet available
alpine/curlapkalpine3.20<=8.12.1-r0Not yet available
alpine/curlapkalpine3.21<8.14.1-r08.14.1-r0
alpine/curlapkalpine3.21<=8.11.0-r2Not yet available
alpine/curlapkalpine3.21<=8.11.1-r0Not yet available
alpine/curlapkalpine3.21<=8.11.1-r1Not yet available
alpine/curlapkalpine3.21<=8.12.0-r0Not yet available
alpine/curlapkalpine3.21<=8.12.1-r0Not yet available
alpine/curlapkalpine3.21<=8.12.1-r1Not yet available
alpine/curlapkalpine3.22<8.14.1-r08.14.1-r0

Severity and metrics

No CVSS data available from this advisory.

NIST

CREATED

UPDATED

ADVISORY IDCVE-2025-5399
EXPLOITABILITY SCORE

3.9

EXPLOITS FOUND
COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

7.5high

Debian

CREATED

UPDATED

ADVISORY IDCVE-2025-5399
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

Ubuntu

CREATED

UPDATED

ADVISORY IDCVE-2025-5399
EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

Alma

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Rocky

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow

Oracle

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

Oracle

CREATED

UPDATED

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Amedium

minimos

CREATED

UPDATED

ADVISORY ID

MINI-ppm5-3j96-36r2

EXPLOITABILITY SCORE

-

EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM ADVISORY