https://seclists.org/oss-sec/2026/q1/31: [ADVISORY] curl CVE-2025-13034: No QUIC certificate pinning with GnuTLS
Published Jan 7, 2026
·Updated
Affected Software
1 affected component
curl>=8.8.0<=8.17.0
Frequently Asked Questions
1
What is the severity of CVE-2025-13034?
CVE-2025-13034 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-13034?
To mitigate CVE-2025-13034, ensure you are using a version of curl that incorporates the fix for the QUIC certificate pinning issue.
3
What does CVE-2025-13034 affect?
CVE-2025-13034 affects the functionality of QUIC certificate pinning when using curl with GnuTLS.
4
Is CVE-2025-13034 an exploit risk?
Yes, CVE-2025-13034 can expose users to man-in-the-middle attacks due to the lack of certificate pinning.
5
Which versions of curl are impacted by CVE-2025-13034?
CVE-2025-13034 affects specific versions of curl that utilize the libcurl library with GnuTLS for QUIC.