CVE-2025-14819

CVE Information
CVE ID
CVE-2025-14819
Severity
MEDIUM CVSS 5.3
Publish Date
2026-01-08
Description

When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.

Collection Date
2026-02-05
Impact Summary
Affected Hosts 2
Related Incidents 0
Related Alerts 0
Affected Hosts (2)
Hostname OS Type Severity Total CVEs
inbridge-ubt-24 LINUX CRITICAL 2336
inbridge-42 LINUX CRITICAL 148