PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14819 Haxx CVE debrief

The CVE-2025-14819 vulnerability in libcurl could lead to accidental reuse of a CA store cached in memory when using TLS-related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option. This could result in libcurl finding and accepting a trust chain that it otherwise would not. Defenders responsible for libcurl usage, especially in applications using TLS-related transfers with reused easy or multi handles, should assess exposure and prioritize verification.

Vendor
Haxx
Product
Curl
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-08
Original CVE updated
2026-09-15
Advisory published
2026-01-08
Advisory updated
2026-09-15

Who should care

Defenders responsible for libcurl usage, especially in applications using TLS-related transfers with reused easy or multi handles, should assess exposure and prioritize verification.

Why it matters

The vulnerability in libcurl could lead to accidental reuse of a CA store cached in memory, potentially allowing for unintended trust chain usage. Defenders should assess exposure and prioritize verification of TLS-related transfers with reused easy or multi handles, especially where the `CURLSSLOPT_NO_PARTIALCHAIN` option is altered.

  • Defenders should verify the usage of the `CURLSSLOPT_NO_PARTIALCHAIN` option and its impact on libcurl behavior.
  • The vulnerability could lead to unintended trust chain usage, potentially affecting the security of TLS-related transfers.
  • Defenders should review and apply patches or updates provided by the vendor to address the vulnerability.

Technical summary

A vulnerability in libcurl could lead to accidental reuse of a CA store cached in memory when using TLS-related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option. This could result in libcurl finding and accepting a trust chain that it otherwise would not. The vulnerability could lead to unintended trust chain usage, potentially affecting the security of TLS-related transfers. Defenders should assess exposure and prioritize verification of TLS-related transfers with reused easy or multi handles in libcurl, especially where the `CURLSSLOPT_NO_PARTIALCHAIN` option is altered.

Defensive priority

Defenders should assess exposure and prioritize verification of TLS-related transfers with reused easy or multi handles in libcurl, especially where the `CURLSSLOPT_NO_PARTIALCHAIN` option is altered.

Recommended defensive actions

  • Assess exposure of libcurl usage to the vulnerability, especially in applications using TLS-related transfers with reused easy or multi handles.
  • Verify the `CURLSSLOPT_NO_PARTIALCHAIN` option usage and its impact on libcurl behavior in the environment.
  • Review and apply patches or updates provided by the vendor to address the vulnerability.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • technicalSummary

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in libcurl, including its description and affected versions. The vulnerability could lead to unintended trust chain usage, potentially affecting the security of TLS-related transfers. Defenders should verify the usage of the `CURLSSLOPT_NO_PARTIALCHAIN` option and its impact on libcurl behavior. The CVE Program record and NVD detail page offer source-provided CVE metadata and official vulnerability assessment.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14819 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14819

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14819 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14819

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://curl.se/docs/CVE-2025-14819.html

    2499f714-1537-4658-8207-48ae4bb9eae9 - Mitigation, Patch, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://curl.se/docs/CVE-2025-14819.json

    2499f714-1537-4658-8207-48ae4bb9eae9 - Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.