CVE-2025-14819: OpenSSL partial chain store policy bypass

Published Dec 31, 2025
·
Updated

Accelerate. An out-of-bounds read was addressed with improved bounds checking.

Other sources

Accounts. A permissions issue was addressed with additional restrictions.

Apple

AirDrop. A reachable assertion was addressed with improved input validation.

Apple

APFS. A buffer overflow was addressed with improved bounds checking.

Apple

App Intents. A logic issue was addressed with improved restrictions.

Apple

AppleJPEG. A memory corruption issue was addressed with improved input validation.

Apple

Credit

Seiji Sakurai@@HeapSmasher, Asaf Cohen, Arash Ale Ebrahim(SCy), Dave G., Vamshi Paili, Tony Gorez for Reverse Society@@tonygo_, CVE-2026-1837, impost0r (ret2plt), Nicholas Soh, David Ige(Beryllium Security), Andreas Jaegersberger & Ro Achterberg(Nosebeard Labs), Arni Hardarson, Niels Hofmans(TrendAI Zero Day Initiative), Anonymous(TrendAI Zero Day Initiative), CVE-2025-14017, CVE-2025-14819, Alex Radocea, Kun Peeks@@SwayZGl1tZyyy, Aswin Kumar Gokula Kannan, Gandalf4a(PKU), Anton Pakhunov, an anonymous researcher, Suresh Sundaram, Jiri Ha, wdszzml, Atuin Automated Vulnerability Discovery Engine, Johnny Franks@@0xjohnny, Google Threat Analysis Group, Mihalis Haatainen, Ari Hawking, Ashish Kunwar, Richard Zana, Dhiyanesh Selvaraj@@redroot97, Somair Ansar, Vaagn Vardanian, Nathaniel Oh@@calysteon, beist, Yiğit Can YILMAZ@@yilmazcanyigit, popku1337(STAR Labs SG Pte), Billy Jheng Bing Jhong(STAR Labs SG Pte), Pan Zhenpeng@@Peterpan0927(STAR Labs SG Pte), Robert Tran, Aswin kumar Gokulakannan, Calif.io in collaboration with Claude, Anthropic Research, Csaba Fitzl@@theevilbit(Iru), Ryan Hileman via Xint Code (xint.io), Chris Betz(Talence Security), Tristan Madani@@TristanInSec(Talence Security), Ruslan Dautov, Prathamesh Walunj@@attahasa, Atul R V, Omar Cerrito, Ricardo Prado, Ian van der Wurff (ian.nl), Michael DePlante@@izobashi(TrendAI Zero Day Initiative), Dan Raviv, Ilya Sc. Jowell A., Peter Malone, Doron Assness, Surya Kushwaha(Supernetworks), Robert Tran(Supernetworks), Peter Malone(Supernetworks), Dave G.(Supernetworks), Alex Radocea(Supernetworks), Pan ZhenPeng@@Peterpan0927(STAR Labs SG Pte), Andy Koo@@andykoo(Hexens), Amy (amys.website), YingQi Shi@@Mas0nShi(DBAppSecurity's WeBin lab), David Ige - Beryllium Security, Cantina, Luke Francis, kwak kiyong / kakaogames, Vitaly Simonovich, Adel Bouachraoui, greenbynox, Do Young Park, Artem Dinaburg(Trail of Bits via Anthropic CVD), Yuhao Hu, Yuanming Lai, Chenggang Wu, Zhe Wang, Idan Masas(TrendAI Zero Day Initiative), DARKNAVY@@DarkNavyOrg(TrendAI Zero Day Initiative), Daniel Rhea, Luka Rački, wac(TrendAI Zero Day Initiative), Kookhwan Lee(TrendAI Zero Day Initiative), Mateusz Krzywicki (iVerify.io), Maher Azzouzi, Aisle offensive security research team (Joshua Rogers(Calif), Luigino Camastra(Calif), Igor Morgenstern(Calif), (Calif), Guido Vranken)(Calif), Maher Azzouzi(Calif), Ngan Nguyen(Calif), dr3dd, Gia Bui@@yabeow(Calif), w0wbox, Milad Nasr, Nicholas Carlini with Claude, Anthropic, Khiem Tran, lebr0nli(National Yang Ming Chiao Tung University), Security, Systems Lab, Kenneth Hsu(Palo Alto Networks), Jérôme DJOUDER, Wang Yu, Brendon Tiszka(Google Project Zero)

Affected Software

4 affected componentsFixes available
redhat/libcurl
haxx curl>=7.87.0<8.18.0
IBM API Connect<=V10.0.8.0 - V10.0.8.9
Apple macOS Tahoe<26.5
26.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 26.5

Event History

Dec 31, 2025
Data Sourced
via Red Hat·04:09 AM
DescriptionSeverityAffected Software
Jan 8, 2026
CVE Published
via MITRE·10:07 AM
Data Sourced
via MITRE·10:07 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 11, 2026
Data Sourced
via Apple·12:00 AM
DescriptionWeaknessAffected Software
Updated
via Apple·12:00 AM
DescriptionWeakness
Jul 7, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is the severity of CVE-2025-14819?

CVE-2025-14819 has been classified with a severity that may impact the security of TLS transfers due to improper handling of CA store caches.

2

How do I fix CVE-2025-14819?

To fix CVE-2025-14819, update to the latest version of libcurl that addresses this vulnerability.

3

What is the impact of CVE-2025-14819 on TLS transfers?

CVE-2025-14819 can lead to the unintended reuse of CA store caches, potentially violating the user's security expectations.

4

Which versions of libcurl are affected by CVE-2025-14819?

CVE-2025-14819 affects all versions of libcurl that allow for TLS transfers while reusing handles with the altered CURLSSLOPT_NO_PARTIALCHAIN option.

5

Who should be concerned about CVE-2025-14819?

Developers and system administrators using affected versions of libcurl for TLS communications should be concerned about CVE-2025-14819.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203