CVE-2025-5399

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/06/2025
Last modified:
30/07/2025

Description

Due to a mistake in libcurl&amp;#39;s WebSocket code, a malicious server can send a<br /> particularly crafted packet which makes libcurl get trapped in an endless<br /> busy-loop.<br /> <br /> There is no other way for the application to escape or exit this loop other<br /> than killing the thread/process.<br /> <br /> This might be used to DoS libcurl-using application.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* 8.13.0 (including) 8.14.1 (excluding)