Количество 11
Количество 11
GHSA-vqhr-m87q-9jqh
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.
CVE-2025-14819
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.
CVE-2025-14819
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.
CVE-2025-14819
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.
CVE-2025-14819
OpenSSL partial chain store policy bypass
CVE-2025-14819
When doing TLS related transfers with reused easy or multi handles and ...
BDU:2026-06682
Уязвимость программного средства для взаимодействия с серверами CURL, позволяющая нарушителю получить доступ к конфиденциальным данным
SUSE-SU-2026:0066-1
Security update for curl
SUSE-SU-2026:0052-1
Security update for curl
SUSE-SU-2026:0050-1
Security update for curl
openSUSE-SU-2026:20031-1
Security update for curl
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-vqhr-m87q-9jqh When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not. | CVSS3: 5.3 | 1% Низкий | 7 месяцев назад | |
CVE-2025-14819 When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not. | CVSS3: 5.3 | 1% Низкий | 7 месяцев назад | |
CVE-2025-14819 When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not. | CVSS3: 6.8 | 1% Низкий | 7 месяцев назад | |
CVE-2025-14819 When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not. | CVSS3: 5.3 | 1% Низкий | 7 месяцев назад | |
CVE-2025-14819 OpenSSL partial chain store policy bypass | 1% Низкий | 7 месяцев назад | ||
CVE-2025-14819 When doing TLS related transfers with reused easy or multi handles and ... | CVSS3: 5.3 | 1% Низкий | 7 месяцев назад | |
BDU:2026-06682 Уязвимость программного средства для взаимодействия с серверами CURL, позволяющая нарушителю получить доступ к конфиденциальным данным | CVSS3: 5.3 | 1% Низкий | 8 месяцев назад | |
SUSE-SU-2026:0066-1 Security update for curl | 7 месяцев назад | |||
SUSE-SU-2026:0052-1 Security update for curl | 7 месяцев назад | |||
SUSE-SU-2026:0050-1 Security update for curl | 7 месяцев назад | |||
openSUSE-SU-2026:20031-1 Security update for curl | 7 месяцев назад |
Уязвимостей на страницу