https://seclists.org/oss-sec/2025/q3/162: [SECURITY ADVISORY] curl: CVE-2025-10148: pdictable WebSocket mask
Published Sep 10, 2025
·Updated
Affected Software
1 affected component
curl curl
Frequently Asked Questions
1
What is the severity of CVE-2025-10148?
CVE-2025-10148 is considered a medium severity vulnerability affecting curl related to a pdictable WebSocket mask.
2
How do I fix CVE-2025-10148?
To fix CVE-2025-10148, update to the latest version of curl where the vulnerability has been patched.
3
What systems are affected by CVE-2025-10148?
CVE-2025-10148 affects all versions of curl that utilize WebSocket functionality.
4
What impact does CVE-2025-10148 have on users?
CVE-2025-10148 may allow attackers to exploit WebSocket masking issues, compromising data integrity.
5
Is CVE-2025-10148 actively being exploited?
As of now, there have been no confirmed reports of active exploitation of CVE-2025-10148.