https://seclists.org/oss-sec/2025/q3/163: [SECURITY ADVISORY] curl: CVE-2025-10148: pdictable WebSocket mask
Published Sep 10, 2025
·Updated
Affected Software
1 affected component
curl curl
Frequently Asked Questions
1
What is the severity of CVE-2025-10148?
CVE-2025-10148 is classified as a medium severity vulnerability due to its potential impact on WebSocket connections.
2
How do I fix CVE-2025-10148?
To fix CVE-2025-10148, update to the latest version of curl that includes the patch addressing this vulnerability.
3
What type of vulnerability is CVE-2025-10148?
CVE-2025-10148 is a vulnerability related to predictable WebSocket masks that can lead to insecure WebSocket implementations.
4
Is CVE-2025-10148 exploitable remotely?
Yes, CVE-2025-10148 is potentially exploitable remotely if the vulnerable version of curl is used in an application that handles WebSocket connections.
5
What versions of curl are affected by CVE-2025-10148?
CVE-2025-10148 affects specific versions of curl that include the websocket functionality without the proper updates.