CVE-2025-5399 log
| Source |
|
| Severity | Low |
| Remote | Yes |
| Type | Denial of service |
| Description | Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the application to escape or exit this loop other than killing the thread/process. This might be used to DoS libcurl-using application. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-2895 | curl | 8.14.0-2 | 8.14.1-1 | Low | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 05 Jun 2025 | ASA-202506-2 | AVG-2895 | curl | Low | denial of service |
| References |
|---|
https://curl.se/docs/CVE-2025-5399.html https://github.com/curl/curl/commit/d1145df24de8f80e6b16 |