CVE-2025-14819Patch(haxx / curl)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch haxx curl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-02-19); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-02-19: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-02-19: 102-1903-1303-1403-1503-24
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-03-131
Patch1
2026-03-141
General1
2026-03-151
Patch1
2026-03-241
Patch1
Full discourse5 posts
  • Deskmodder@deskmodder
    Patch

    Notepad++ 8.9.3 mit einigen Korrekturen und einer berbesserten SIcherheit für cURL (CVE-2025-14819) Für Notepad++ steht ein neues Update auf die Version 8.9.3 bereit. In dieser Version wurden eine Rei... https://www.deskmodder.de/blog/2026/03/24/notepad-8-9-3-mit-einigen-korrekturen-und-einer-berbesserten-sicherheit-fuer-curl-cve-2025-14819/

    Post summary

    Notepad++ version 8.9.3 includes updates with enhanced security for cURL to address CVE‑2025‑14819, but the post does not provide exploit or vulnerability details.

    00000143
    98 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-14819 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/411 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS has removed CVE-2025-14819 from its latest Lambda base images, indicating the vulnerability has been fixed or patched.

    00000138
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-14819 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/411 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE‑2025‑14819 has been removed from the latest AWS Lambda base images, with no further exploitation or patch details given.

    00000136
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-14819 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/411 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog confirms that CVE‑2025‑14819 is no longer present in the latest AWS Lambda base images, indicating the vulnerability has been addressed.

    00000122
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2025-14819 impacts curl-minimal in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/411 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new medium‑severity CVE (CVE‑2025‑14819) affecting curl‑minimal in AWS Lambda base images has been reported, with details linked to a GitHub issue.

    0000036
    30 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more