CVE-2025-14017

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/01/2026
Last modified:
27/01/2026

Description

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,<br /> changing TLS options in one thread would inadvertently change them globally<br /> and therefore possibly also affect other concurrently setup transfers.<br /> <br /> Disabling certificate verification for a specific transfer could<br /> unintentionally disable the feature for other threads as well.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* 7.17.0 (including) 8.18.0 (excluding)