CVE-2025-14017: broken TLS options for threaded LDAPS

Published Jan 7, 2026
·
Updated

Accelerate. An out-of-bounds read was addressed with improved bounds checking.

Other sources

Accounts. A permissions issue was addressed with additional restrictions.

Apple

AirDrop. A reachable assertion was addressed with improved input validation.

Apple

APFS. A buffer overflow was addressed with improved bounds checking.

Apple

App Intents. A logic issue was addressed with improved restrictions.

Apple

AppleJPEG. A memory corruption issue was addressed with improved input validation.

Apple

Credit

Seiji Sakurai@@HeapSmasher, Asaf Cohen, Arash Ale Ebrahim(SCy), Dave G., Vamshi Paili, Tony Gorez for Reverse Society@@tonygo_, CVE-2026-1837, impost0r (ret2plt), Nicholas Soh, David Ige(Beryllium Security), Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), Arni Hardarson, Niels Hofmans(TrendAI Zero Day Initiative), Anonymous(TrendAI Zero Day Initiative), CVE-2025-14017, CVE-2025-14819, Alex Radocea, Kun Peeks@@SwayZGl1tZyyy, Aswin Kumar Gokula Kannan, Gandalf4a(PKU), Anton Pakhunov, an anonymous researcher, Suresh Sundaram, Jiri Ha, wdszzml, Atuin Automated Vulnerability Discovery Engine, Johnny Franks@@0xjohnny, Google Threat Analysis Group, Mihalis Haatainen, Ari Hawking, Ashish Kunwar, Richard Zana, Dhiyanesh Selvaraj@@redroot97, Somair Ansar, Vaagn Vardanian, Nathaniel Oh@@calysteon, beist, Yiğit Can YILMAZ@@yilmazcanyigit, popku1337(STAR Labs SG Pte), Billy Jheng Bing Jhong(STAR Labs SG Pte), Pan Zhenpeng@@Peterpan0927(STAR Labs SG Pte), Robert Tran, Aswin kumar Gokulakannan, Calif.io in collaboration with Claude, Anthropic Research, Csaba Fitzl@@theevilbit(Iru), Ryan Hileman via Xint Code (xint.io), Chris Betz(Talence Security), Tristan Madani@@TristanInSec(Talence Security), Ruslan Dautov, Prathamesh Walunj@@attahasa, Atul R V, Omar Cerrito, Ricardo Prado, Ian van der Wurff (ian.nl), Michael DePlante@@izobashi(TrendAI Zero Day Initiative), Dan Raviv, Ilya Sc. Jowell A., Peter Malone, Doron Assness, Surya Kushwaha(Supernetworks), Robert Tran(Supernetworks), Peter Malone(Supernetworks), Dave G.(Supernetworks), Alex Radocea(Supernetworks), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Andy Koo@@andykoo(Hexens), Amy (amys.website), YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), David Ige - Beryllium Security, Cantina, Luke Francis, kwak kiyong / kakaogames, Vitaly Simonovich, Adel Bouachraoui, greenbynox, Do Young Park, Artem Dinaburg(Trail of Bits via Anthropic CVD), Yuhao Hu, Yuanming Lai, Chenggang Wu, Zhe Wang, Idan Masas(TrendAI Zero Day Initiative), DARKNAVY@@DarkNavyOrg(TrendAI Zero Day Initiative), Daniel Rhea, Luka Rački, wac(TrendAI Zero Day Initiative), Kookhwan Lee(TrendAI Zero Day Initiative), Mateusz Krzywicki (iVerify.io), Maher Azzouzi, Aisle offensive security research team (Joshua Rogers(Calif), Luigino Camastra(Calif), Igor Morgenstern(Calif), (Calif), Guido Vranken)(Calif), Maher Azzouzi(Calif), Ngan Nguyen(Calif), dr3dd, Gia Bui@@yabeow(Calif), w0wbox, Milad Nasr, Nicholas Carlini with Claude, Anthropic, Khiem Tran, lebr0nli(National Yang Ming Chiao Tung University), Security, Systems Lab, Kenneth Hsu(Palo Alto Networks), Jérôme DJOUDER, Wang Yu, Brendon Tiszka(Google Project Zero)

Affected Software

10 affected componentsFixes available
redhat/libcurl
haxx curl>=7.17.0<8.18.0
Microsoft azl3 cmake 3.30.3-11
Microsoft cbl2 cmake 3.21.4-21
Microsoft cbl2 curl 8.8.0-8
Microsoft azl3 curl 8.11.1-5
Microsoft cbl2 cmake 3.21.4-20
Microsoft azl3 cmake 3.30.3-10
IBM API Connect<=V10.0.8.0 - V10.0.8.9
Apple macOS Tahoe<26.5
26.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 26.5

Event History

Jan 8, 2026
CVE Published
via MITRE·10:07 AM
Data Sourced
via MITRE·10:07 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityAffected Software
Jan 9, 2026
Data Sourced
via Microsoft·09:09 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·09:09 AM
Affected Software
Updated
via Microsoft·09:09 AM
Affected Software
Updated
via Microsoft·09:09 AM
DescriptionSeverity
May 11, 2026
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2025-14017?

The severity of CVE-2025-14017 is considered moderate due to potential security risks from altered TLS options affecting multiple transfers.

2

How do I fix CVE-2025-14017?

To fix CVE-2025-14017, update to the latest version of libcurl where the vulnerability is patched.

3

What are the potential impacts of CVE-2025-14017?

The potential impacts of CVE-2025-14017 include compromised security through unintended changes in TLS settings during concurrent LDAPS transfers.

4

Which software is affected by CVE-2025-14017?

CVE-2025-14017 affects the libcurl library, specifically the Red Hat distribution of libcurl.

5

Can CVE-2025-14017 affect the confidentiality of data?

Yes, CVE-2025-14017 can affect the confidentiality of data by allowing unauthorized changes to TLS security protocols during transfers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203