Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-10148

Опубликовано: 12 сент. 2025
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS3: 5.3

Описание

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.

РелизСтатусПримечание
devel

needed

esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

needed

plucky

ignored

end of life, was needed
questing

needed

upstream

released

8.16.0-1

Показывать по

EPSS

Процентиль: 23%
0.00078
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
5 месяцев назад

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.

CVSS3: 5.3
nvd
5 месяцев назад

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.

CVSS3: 5.3
debian
5 месяцев назад

curl's websocket code did not update the 32 bit mask pattern for each ...

CVSS3: 5.3
github
5 месяцев назад

curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.

suse-cvrf
5 месяцев назад

Security update for curl

EPSS

Процентиль: 23%
0.00078
Низкий

5.3 Medium

CVSS3