CVE-2025-14017

Published: January 9, 2026Last modified: January 15, 2026

Description

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.

Severity score breakdown

ParameterValue
Base score6.3
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactNONE
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Status

ProductReleasePackageStatus
Alpaquita LinuxStreamcurlFixed (8.18.0-r0)
Hardened ContainersStreamcurlFixed (8.18.0-r0)

References

ON THIS PAGE