CVE-2025-14017Patch(haxx / curl)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haxx curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-567

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-01-28); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-01-28: 1Mentions · 2026-02-19: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Patch / Workaround · 2026-01-28: 1Patch / Workaround · 2026-03-14: 1Technical Details · 2026-01-28: 101-2802-1903-1303-1403-15
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-281
Patch1
2026-02-191
Disclosure1
2026-03-131
Patch1
2026-03-141
Patch1
2026-03-151
General1
Full discourse5 posts
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-14017 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/409 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post notes that CVE‑2025‑14017 is no longer found in recent AWS Lambda base images, but provides no further exploit or patch details.

    00000138
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-14017 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/409 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post indicates that AWS Lambda base image scans no longer flag CVE-2025-14017, implying the vulnerability has been remediated in newer images.

    00000134
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-14017 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/409 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE‑2025‑14017 has been removed from the latest AWS Lambda base images, implying the issue is no longer present.

    00000117
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2025-14017 impacts curl-minimal in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/409 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    The post announces the detection of CVE‑2025‑14017 in AWS Lambda’s curl‑minimal images but does not provide exploitation details or mitigation advice.

    0000035
    30 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical security update analysis published: CVE-2025-14017 in curl for #Fedora 42 Just analyzed the recently patched TLS vulnerability affecting threaded LDAPS operations in curl. Read more: 👉 https://tinyurl.com/2a9d2kss #Security https://t.co/T8hL8BLs3S

    Post summary

    The post is an analysis of CVE‑2025‑14017, a TLS flaw in curl affecting threaded LDAPS, noting it has been patched for Fedora 42, with no PoC, exploit tool, or active exploitation mentioned.

    0000067
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more