CVE-2025-5399
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/06/2025
Last modified:
30/07/2025
Description
Due to a mistake in libcurl&#39;s WebSocket code, a malicious server can send a<br />
particularly crafted packet which makes libcurl get trapped in an endless<br />
busy-loop.<br />
<br />
There is no other way for the application to escape or exit this loop other<br />
than killing the thread/process.<br />
<br />
This might be used to DoS libcurl-using application.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | 8.13.0 (including) | 8.14.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page