CVE-2025-10148
Gravedad CVSS v3.1:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
12/09/2025
Última modificación:
20/01/2026
Descripción
*** Pendiente de traducción *** curl&#39;s websocket code did not update the 32 bit mask pattern for each new<br />
outgoing frame as the specification says. Instead it used a fixed mask that<br />
persisted and was used throughout the entire connection.<br />
<br />
A predictable mask pattern allows for a malicious server to induce traffic<br />
between the two communicating parties that could be interpreted by an involved<br />
proxy (configured or transparent) as genuine, real, HTTP traffic with content<br />
and thereby poison its cache. That cached poisoned content could then be<br />
served to all users of that proxy.
Impacto
Puntuación base 3.x
5.30
Gravedad 3.x
MEDIA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | 8.11.0 (incluyendo) | 8.16.0 (excluyendo) |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página



