CVE-2025-14819: OpenSSL partial chain store policy bypass
Accelerate. An out-of-bounds read was addressed with improved bounds checking.
Other sources
Accounts. A parsing issue in the handling of directory paths was addressed with improved path validation.
— Apple
Accounts. A permissions issue was addressed with additional restrictions.
— Apple
Accounts. An authorization issue was addressed with improved state management.
— Apple
afpfs. A buffer overflow was addressed with improved bounds checking.
— Apple
AirDrop. A reachable assertion was addressed with improved input validation.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 26.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.7.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.8.8 - Configuration
For TLS-related transfers using reused easy or multi handles, avoid changing (or reversing) the CURLSSLOPT_NO_PARTIALCHAIN option. Keep the option value consistent so libcurl does not accept an OpenSSL trust chain it otherwise would not when a CA store cached in memory is reused.
curl (libcurl) CURLSSLOPT_NO_PARTIALCHAIN = Do not alter/flip this option during TLS transfers; ensure the option is kept consistent so partial chain stopolicy bypass cannot occur with reused easy or multi handles
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-28991
- CVE-2026-28988
- CVE-2026-43667
- CVE-2026-28959
- CVE-2026-28995
- CVE-2026-1837
- CVE-2026-28956
- CVE-2026-39869
- CVE-2026-28849
- CVE-2026-28922
- CVE-2026-28936
- CVE-2026-28918
- CVE-2026-28915
- CVE-2025-14017
- CVE-2025-14819
- CVE-2026-43659
- CVE-2026-28923
- CVE-2026-28925
- CVE-2026-43661
- CVE-2026-28977
- CVE-2026-28990
- CVE-2026-28978
- CVE-2026-28992
- CVE-2026-28943
- CVE-2026-28969
- CVE-2026-39877
- CVE-2026-43655
- CVE-2026-43654
- CVE-2026-28908
- CVE-2026-28954
- CVE-2026-28897
- CVE-2026-28952
- CVE-2026-28951
- CVE-2026-28972
- CVE-2026-28986
- CVE-2026-28987
- CVE-2026-28983
- CVE-2026-28900
- CVE-2026-28929
- CVE-2026-43653
- CVE-2026-28985
- CVE-2026-43668
- CVE-2026-43666
- CVE-2026-28941
- CVE-2026-28940
- CVE-2026-28961
- CVE-2026-28906
- CVE-2026-43656
- CVE-2026-43652
- CVE-2026-39870
- CVE-2026-28846
- CVE-2026-28993
- CVE-2026-28848
- CVE-2026-28930
- CVE-2026-28974
- CVE-2026-28996
- CVE-2026-28919
- CVE-2026-28924
- CVE-2026-39871
- CVE-2026-28976
- CVE-2026-43660
- CVE-2026-28907
- CVE-2026-28962
- CVE-2026-43658
- CVE-2026-28984
- CVE-2026-28905
- CVE-2026-28847
- CVE-2026-28904
- CVE-2026-28955
- CVE-2026-28903
- CVE-2026-28953
- CVE-2026-28902
- CVE-2026-28901
- CVE-2026-28913
- CVE-2026-28883
- CVE-2026-28958
- CVE-2026-28917
- CVE-2026-28947
- CVE-2026-28946
- CVE-2026-28942
- CVE-2026-28971
- CVE-2026-43670
- CVE-2026-28944
- CVE-2026-28819
- CVE-2026-28994
- CVE-2026-28914
- CVE-2026-28920
- CVE-2026-43749
- CVE-2026-65404
- CVE-2026-64767
- CVE-2026-43815
- CVE-2026-23918
- CVE-2026-64695
- CVE-2026-43801
- CVE-2026-43781
- CVE-2026-64737
- CVE-2026-43748
- CVE-2026-43776
- CVE-2026-43681
- CVE-2026-43761
- CVE-2026-43672
- CVE-2026-43763
- CVE-2026-64702
- CVE-2026-64725
- CVE-2026-64747
- CVE-2026-64762
- CVE-2026-64707
- CVE-2026-64698
- CVE-2026-64734
- CVE-2026-43756
- CVE-2026-43693
- CVE-2026-43673
- CVE-2026-43744
- CVE-2026-43803
- CVE-2026-43775
- CVE-2026-43711
- CVE-2026-43738
- CVE-2026-84489
- CVE-2026-43802
- CVE-2026-64710
- CVE-2026-39875
- CVE-2026-64701
- CVE-2026-43698
- CVE-2026-3784
- CVE-2026-3783
- CVE-2026-43758
- CVE-2026-64708
- CVE-2026-28926
- CVE-2026-43747
- CVE-2026-64694
- CVE-2026-28945
- CVE-2026-64776
- CVE-2026-43793
- CVE-2026-43753
- CVE-2026-43714
- CVE-2026-64740
- CVE-2026-43796
- CVE-2026-64692
- CVE-2026-43682
- CVE-2026-28981
- CVE-2026-43773
- CVE-2026-43767
- CVE-2026-64697
- CVE-2026-43764
- CVE-2026-43710
- CVE-2025-43325
- CVE-2026-64716
- CVE-2026-43780
- CVE-2026-43818
- CVE-2026-64754
- CVE-2026-64693
- CVE-2026-64714
- CVE-2026-43805
- CVE-2026-64749
- CVE-2026-43782
- CVE-2026-64744
- CVE-2026-64775
- CVE-2026-28982
- CVE-2026-43778
- CVE-2026-64735
- CVE-2026-43822
- CVE-2026-64700
- CVE-2026-43799
- CVE-2026-43810
- CVE-2026-43724
- CVE-2026-43722
- CVE-2026-43809
- CVE-2026-43757
- CVE-2026-43769
- CVE-2026-43754
- CVE-2026-64723
- CVE-2026-39868
- CVE-2026-64709
- CVE-2026-64721
- CVE-2026-64717
- CVE-2026-20672
- CVE-2026-4424
- CVE-2026-28973
- CVE-2026-64739
- CVE-2026-43703
- CVE-2026-43706
- CVE-2026-43766
- CVE-2026-64738
- CVE-2026-64724
- CVE-2026-43723
- CVE-2026-43807
- CVE-2026-43733
- CVE-2026-43729
- CVE-2026-64772
- CVE-2026-64774
- CVE-2026-64770
- CVE-2026-64769
- CVE-2026-64722
- CVE-2026-64768
- CVE-2026-64771
- CVE-2026-43771
- CVE-2026-43772
- CVE-2026-64711
- CVE-2026-28912
- CVE-2026-43765
- CVE-2026-28896
- CVE-2026-28933
- CVE-2026-64731
- CVE-2026-43812
- CVE-2026-43694
- CVE-2026-39874
- CVE-2026-64764
- CVE-2026-64763
- CVE-2026-64766
- CVE-2026-64765
- CVE-2026-43779
- CVE-2026-43777
- CVE-2026-43665
- CVE-2026-64745
- CVE-2026-39873
- CVE-2026-64696
- CVE-2026-64704
- CVE-2026-43774
- CVE-2026-43770
- CVE-2026-43768
- CVE-2026-64703
- CVE-2026-64699
- CVE-2026-43750
- CVE-2026-28932
- CVE-2026-28836
- CVE-2026-28911
- CVE-2026-86902
- CVE-2026-43760
- CVE-2026-43755
Frequently Asked Questions
What is the severity of CVE-2025-14819?
CVE-2025-14819 has been classified with a severity that may impact the security of TLS transfers due to improper handling of CA store caches.
How do I fix CVE-2025-14819?
To fix CVE-2025-14819, update to the latest version of libcurl that addresses this vulnerability.
What is the impact of CVE-2025-14819 on TLS transfers?
CVE-2025-14819 can lead to the unintended reuse of CA store caches, potentially violating the user's security expectations.
Which versions of libcurl are affected by CVE-2025-14819?
CVE-2025-14819 affects all versions of libcurl that allow for TLS transfers while reusing handles with the altered CURLSSLOPT_NO_PARTIALCHAIN option.
Who should be concerned about CVE-2025-14819?
Developers and system administrators using affected versions of libcurl for TLS communications should be concerned about CVE-2025-14819.