CVE-2025-14819

Source
https://cve.org/CVERecord?id=CVE-2025-14819
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14819.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-14819
Aliases
Downstream
Related
Published
2026-01-08T10:07:54Z
Modified
2026-09-17T03:30:51Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
OpenSSL partial chain store policy bypass
Details

When doing TLS related transfers with reused easy or multi handles and altering the CURLSSLOPT_NO_PARTIALCHAIN option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.

Database specific
{
    "cna_assigner": "curl",
    "cwe_ids": [
        "CWE-295"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14819.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "7.87.0"
                },
                {
                    "fixed": "8.14.2"
                },
                {
                    "introduced": "8.15.0"
                },
                {
                    "fixed": "8.16.1"
                },
                {
                    "introduced": "3c16697ebd796f799227be293e8689aec5f8190d"
                },
                {
                    "fixed": "cd046f6c93b39d673a58c18648d8906e954c4f5d"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/curl/curl

Affected ranges

Type
GIT
Repo
https://github.com/curl/curl
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "7.87.0"
        },
        {
            "fixed": "8.18.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

7.*
7.87.0
7.88.0
7.88.1
8.*
8.0.0
8.0.1
8.1.0
8.1.1
8.1.2
8.10.0
8.10.1
8.11.0
8.11.1
8.12.0
8.12.1
8.13.0
8.14.0
8.14.1
8.15.0
8.16.0
8.2.0
8.2.1
8.3.0
8.4.0
8.5.0
8.6.0
8.7.0
8.7.1
8.8.0
8.9.0
8.9.1
Other
curl-7_87_0
curl-7_88_0
curl-7_88_1
curl-8_0_0
curl-8_0_1
curl-8_10_0
curl-8_10_1
curl-8_11_0
curl-8_11_1
curl-8_12_0
curl-8_12_1
curl-8_13_0
curl-8_14_0
curl-8_14_1
curl-8_15_0
curl-8_16_0
curl-8_17_0
curl-8_1_0
curl-8_1_1
curl-8_1_2
curl-8_2_0
curl-8_2_1
curl-8_3_0
curl-8_4_0
curl-8_5_0
curl-8_6_0
curl-8_7_0
curl-8_7_1
curl-8_8_0
curl-8_9_0
curl-8_9_1
rc-8_18_0-1
rc-8_18_0-2
rc-8_18_0-3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14819.json"