Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-11563

Опубликовано: 25 фев. 2026
Источник: debian
EPSS Низкий

Описание

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
curlfixed8.17.0-2package
curlfixed8.14.1-2+deb13u2trixiepackage
curlnot-affectedbookwormpackage
curlnot-affectedbullseyepackage

Примечания

  • Introduced with: https://github.com/curl/wcurl/commit/e01d578582a23695ee3cec08a2bff29d61a0bfb4 (v2024.12.08)

  • Fixed by: https://github.com/curl/wcurl/commit/524f7e733237cd26553dfd76adda521d3150d852 (v2025.11.04)

  • Introduced with: https://github.com/curl/curl/commit/23bed347b38922779382599f8b72c4d762add7bd (curl-8_14_0)

  • Fixed by: https://github.com/curl/curl/commit/fb0c014e30e5f4de7aa0d566c52c836a6423da29 (rc-8_17_0-3)

  • Included in Debian since 8.8.0-2

  • https://curl.se/docs/CVE-2025-11563.html

  • Followup for incomplete fix: https://github.com/curl/wcurl/pull/75

EPSS

Процентиль: 4%
0.00017
Низкий

Связанные уязвимости

CVSS3: 4.6
ubuntu
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

CVSS3: 6.5
redhat
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

CVSS3: 4.6
nvd
около 1 месяца назад

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

msrc
около 1 месяца назад

wcurl path traversal with percent-encoded slashes

suse-cvrf
4 месяца назад

Security update for curl

EPSS

Процентиль: 4%
0.00017
Низкий