Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-432 Medium 6.5

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a...

JLSEC Published
Modified
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Packages
CURL_jll >= 8.9.0+0, < 8.14.1+0
LibCURL_jll >= 8.8.0+0, < 8.14.1+0
Aliases / Upstream
CVE-2025-4947 GHSA-ppfq-jg49-mqj4 EUVD-2025-16303

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

References