PatchSiren cyber security CVE debrief
CVE-2025-14819 Haxx CVE debrief
The CVE-2025-14819 vulnerability in libcurl could lead to accidental reuse of a CA store cached in memory when using TLS-related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option. This could result in libcurl finding and accepting a trust chain that it otherwise would not. Defenders responsible for libcurl usage, especially in applications using TLS-related transfers with reused easy or multi handles, should assess exposure and prioritize verification.
- Vendor
- Haxx
- Product
- Curl
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-08
- Original CVE updated
- 2026-09-15
- Advisory published
- 2026-01-08
- Advisory updated
- 2026-09-15
Who should care
Defenders responsible for libcurl usage, especially in applications using TLS-related transfers with reused easy or multi handles, should assess exposure and prioritize verification.
Why it matters
The vulnerability in libcurl could lead to accidental reuse of a CA store cached in memory, potentially allowing for unintended trust chain usage. Defenders should assess exposure and prioritize verification of TLS-related transfers with reused easy or multi handles, especially where the `CURLSSLOPT_NO_PARTIALCHAIN` option is altered.
- Defenders should verify the usage of the `CURLSSLOPT_NO_PARTIALCHAIN` option and its impact on libcurl behavior.
- The vulnerability could lead to unintended trust chain usage, potentially affecting the security of TLS-related transfers.
- Defenders should review and apply patches or updates provided by the vendor to address the vulnerability.
Technical summary
A vulnerability in libcurl could lead to accidental reuse of a CA store cached in memory when using TLS-related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option. This could result in libcurl finding and accepting a trust chain that it otherwise would not. The vulnerability could lead to unintended trust chain usage, potentially affecting the security of TLS-related transfers. Defenders should assess exposure and prioritize verification of TLS-related transfers with reused easy or multi handles in libcurl, especially where the `CURLSSLOPT_NO_PARTIALCHAIN` option is altered.
Defensive priority
Defenders should assess exposure and prioritize verification of TLS-related transfers with reused easy or multi handles in libcurl, especially where the `CURLSSLOPT_NO_PARTIALCHAIN` option is altered.
Recommended defensive actions
- Assess exposure of libcurl usage to the vulnerability, especially in applications using TLS-related transfers with reused easy or multi handles.
- Verify the `CURLSSLOPT_NO_PARTIALCHAIN` option usage and its impact on libcurl behavior in the environment.
- Review and apply patches or updates provided by the vendor to address the vulnerability.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- technicalSummary
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in libcurl, including its description and affected versions. The vulnerability could lead to unintended trust chain usage, potentially affecting the security of TLS-related transfers. Defenders should verify the usage of the `CURLSSLOPT_NO_PARTIALCHAIN` option and its impact on libcurl behavior. The CVE Program record and NVD detail page offer source-provided CVE metadata and official vulnerability assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-14819 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-14819
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-14819 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14819
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://curl.se/docs/CVE-2025-14819.html
2499f714-1537-4658-8207-48ae4bb9eae9 - Mitigation, Patch, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://curl.se/docs/CVE-2025-14819.json
2499f714-1537-4658-8207-48ae4bb9eae9 - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.