CVE-2025-10148
CVE-2025-10148 is a medium-severity vulnerability in Haxx Curl with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-340.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 0% (41st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-29013
- Weakness: CWE-340
- Affected product: Haxx Curl
- Published:
- Last modified:
Description
curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.
Frequently asked questions
- What is CVE-2025-10148?
- curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.
- How severe is CVE-2025-10148?
- CVE-2025-10148 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2025-10148 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (41st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-10148?
- CVE-2025-10148 affects Haxx Curl. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-10148?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-10148 have an EU (EUVD) identifier?
- Yes. CVE-2025-10148 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-29013.
- When was CVE-2025-10148 published?
- CVE-2025-10148 was published on 2025-09-12 and last updated on 2026-09-15.
References
- https://curl.se/docs/CVE-2025-10148.html
- https://curl.se/docs/CVE-2025-10148.json
- https://hackerone.com/reports/3330839
- http://www.openwall.com/lists/oss-security/2025/09/10/2
- http://www.openwall.com/lists/oss-security/2025/09/10/3
- http://www.openwall.com/lists/oss-security/2025/09/10/4
Affected products (1)
- cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
More vulnerabilities in Haxx Curl
- CVE-2026-19931 — Critical (CVSS 9.8): A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication,…
- CVE-2026-9079 — Critical (CVSS 9.8): libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the…
- CVE-2026-8925 — Critical (CVSS 9.8): The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing…
- CVE-2026-11856 — Critical (CVSS 9.8): Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then…
- CVE-2026-10536 — Critical (CVSS 9.8): A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via…
- CVE-2022-32221 — Critical (CVSS 9.8): When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data…
All CVEs affecting Haxx Curl →
Other CWE-340 vulnerabilities
- CVE-2025-69286 — Critical (CVSS 9.8): RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an…
- CVE-2026-75106 — Critical (CVSS 9.1): OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt,…
- CVE-2026-5081 — Critical (CVSS 9.1): Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are…
- CVE-2026-85496 — High (CVSS 8.8): The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a…
- CVE-2026-2473 — High (CVSS 7.7): Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not…
- CVE-2026-95653 — High (CVSS 7.5): Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps…