https://seclists.org/oss-sec/2026/q1/32: [ADVISORY] curl CVE-2025-14017: broken TLS options for thaded LDAPS
Published Jan 7, 2026
·Updated
Affected Software
1 affected component
curl>=7.17.0<=8.17.0
Frequently Asked Questions
1
What is the severity of CVE-2025-14017?
CVE-2025-14017 has been classified as a medium severity vulnerability that affects multithreaded LDAPS transfers with libcurl.
2
How do I fix CVE-2025-14017?
To fix CVE-2025-14017, update to the latest version of curl where the TLS options for threaded LDAPS have been corrected.
3
What software is affected by CVE-2025-14017?
CVE-2025-14017 affects the curl software when performing multithreaded LDAPS operations.
4
What type of attack does CVE-2025-14017 allow?
CVE-2025-14017 could potentially lead to improper TLS option handling during LDAPS transfers, which may expose vulnerabilities to attackers.
5
When was CVE-2025-14017 published?
CVE-2025-14017 was published on January 7, 2026.