Description

When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.

INFO

Published Date :

2026-01-08T10:07:54.408Z

Last Modified :

2026-01-08T15:02:04.303Z

Source :

curl
AFFECTED PRODUCTS

The following products are affected by CVE-2025-14819 vulnerability.

Vendors Products
Curl
  • Curl
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-14819.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact