https://seclists.org/oss-sec/2026/q1/34: [ADVISORY] curl CVE-2025-14819: OpenSSL partial chain stopolicy bypass
Published Jan 7, 2026
·Updated
Affected Software
1 affected component
curl>=7.87.0<=8.17.0
Frequently Asked Questions
1
What is the severity of CVE-2025-14819?
CVE-2025-14819 is classified as a moderate severity vulnerability affecting curl due to an OpenSSL partial chain store policy bypass.
2
How do I fix CVE-2025-14819?
To fix CVE-2025-14819, update curl to the latest version that addresses this vulnerability.
3
What software versions are affected by CVE-2025-14819?
CVE-2025-14819 affects certain versions of curl that utilize OpenSSL for TLS-related transfers.
4
What types of attacks does CVE-2025-14819 allow?
CVE-2025-14819 potentially allows attackers to bypass intended certificate validation policies during TLS connections.
5
Is CVE-2025-14819 critical for all curl users?
Not all curl users are critically affected by CVE-2025-14819, but those using re-used easy or multi handles should apply the fix.