https://seclists.org/oss-sec/2025/q4/127: [SECURITY ADVISORY] wcurl path traversal with percent-encoded slashes
Published Nov 4, 2025
·Updated
Affected Software
2 affected components
redhat/curl>=8.14.0<=8.16.0
redhat/wcurl>=2024.12.08<=2025.09.27
Frequently Asked Questions
1
What is the severity of CVE-2025-11563?
CVE-2025-11563 has been classified as a high severity vulnerability due to its potential for leading to path traversal attacks.
2
How do I fix CVE-2025-11563?
To fix CVE-2025-11563, update to the latest version of curl or wcurl that addresses this vulnerability.
3
What type of attack does CVE-2025-11563 facilitate?
CVE-2025-11563 facilitates path traversal attacks through the exploitation of percent-encoded slashes in URLs.
4
Which software is affected by CVE-2025-11563?
CVE-2025-11563 affects the redhat/curl and redhat/wcurl software packages.
5
When was CVE-2025-11563 published?
CVE-2025-11563 was published on November 4, 2025.