CVE-2025-14819

Source
https://cve.org/CVERecord?id=CVE-2025-14819
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-14819.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-14819
Aliases
Downstream
Related
Published
2026-01-08T10:07:54.408Z
Modified
2026-05-18T05:56:14.082132795Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
OpenSSL partial chain store policy bypass
Details

When doing TLS related transfers with reused easy or multi handles and altering the CURLSSLOPT_NO_PARTIALCHAIN option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "last_affected": "8.17.0"
                },
                {
                    "last_affected": "8.16.0"
                },
                {
                    "last_affected": "8.15.0"
                },
                {
                    "last_affected": "8.14.1"
                },
                {
                    "last_affected": "8.14.0"
                },
                {
                    "last_affected": "8.13.0"
                },
                {
                    "last_affected": "8.12.1"
                },
                {
                    "last_affected": "8.12.0"
                },
                {
                    "last_affected": "8.11.1"
                },
                {
                    "last_affected": "8.11.0"
                },
                {
                    "last_affected": "8.10.1"
                },
                {
                    "last_affected": "8.10.0"
                },
                {
                    "last_affected": "8.9.1"
                },
                {
                    "last_affected": "8.9.0"
                },
                {
                    "last_affected": "8.8.0"
                },
                {
                    "last_affected": "8.7.1"
                },
                {
                    "last_affected": "8.7.0"
                },
                {
                    "last_affected": "8.6.0"
                },
                {
                    "last_affected": "8.5.0"
                },
                {
                    "last_affected": "8.4.0"
                },
                {
                    "last_affected": "8.3.0"
                },
                {
                    "last_affected": "8.2.1"
                },
                {
                    "last_affected": "8.2.0"
                },
                {
                    "last_affected": "8.1.2"
                },
                {
                    "last_affected": "8.1.1"
                },
                {
                    "last_affected": "8.1.0"
                },
                {
                    "last_affected": "8.0.1"
                },
                {
                    "last_affected": "8.0.0"
                },
                {
                    "last_affected": "7.88.1"
                },
                {
                    "last_affected": "7.88.0"
                },
                {
                    "last_affected": "7.87.0"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14819.json",
    "cna_assigner": "curl"
}
References

Affected packages

Git / github.com/curl/curl

Affected ranges

Type
GIT
Repo
https://github.com/curl/curl
Events
Database specific
{
    "cpe": "cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*",
    "source": "CPE_FIELD",
    "extracted_events": [
        {
            "introduced": "7.87.0"
        },
        {
            "fixed": "8.18.0"
        }
    ]
}

Affected versions

Other
curl-7_87_0
curl-7_88_0
curl-7_88_1
curl-8_0_0
curl-8_0_1
curl-8_10_0
curl-8_10_1
curl-8_11_0
curl-8_11_1
curl-8_12_0
curl-8_12_1
curl-8_13_0
curl-8_14_0
curl-8_14_1
curl-8_15_0
curl-8_16_0
curl-8_17_0
curl-8_1_0
curl-8_1_1
curl-8_1_2
curl-8_2_0
curl-8_2_1
curl-8_3_0
curl-8_4_0
curl-8_5_0
curl-8_6_0
curl-8_7_0
curl-8_7_1
curl-8_8_0
curl-8_9_0
curl-8_9_1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-14819.json"