libcurl TLS CA Cache Bypass via CURLSSLOPT_NO_PARTIALCHAIN
CVE-2025-14819 Published on January 8, 2026
OpenSSL partial chain store policy bypass
When doing TLS related transfers with reused easy or multi handles and
altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally
reuse a CA store cached in memory for which the partial chain option was
reversed. Contrary to the user's wishes and expectations. This could make
libcurl find and accept a trust chain that it otherwise would not.
Vulnerability Analysis
CVE-2025-14819 can be exploited with network access, requires user interaction. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2025-14819
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-14819 are published in these products:
Affected Versions
curl:- Version 7.87.0 and below 8.14.2 is affected.
- Version 8.15.0 and below 8.16.1 is affected.
- Version 8.17.0 and below 8.18.0 is affected.
- Version 3c16697ebd796f799227be293e8689aec5f8190d and below cd046f6c93b39d673a58c18648d8906e954c4f5d is affected.
- Version 8.17.0 is affected.
- Version 8.16.0 is affected.
- Version 8.15.0 is affected.
- Version 8.14.1 is affected.
- Version 8.14.0 is affected.
- Version 8.13.0 is affected.
- Version 8.12.1 is affected.
- Version 8.12.0 is affected.
- Version 8.11.1 is affected.
- Version 8.11.0 is affected.
- Version 8.10.1 is affected.
- Version 8.10.0 is affected.
- Version 8.9.1 is affected.
- Version 8.9.0 is affected.
- Version 8.8.0 is affected.
- Version 8.7.1 is affected.
- Version 8.7.0 is affected.
- Version 8.6.0 is affected.
- Version 8.5.0 is affected.
- Version 8.4.0 is affected.
- Version 8.3.0 is affected.
- Version 8.2.1 is affected.
- Version 8.2.0 is affected.
- Version 8.1.2 is affected.
- Version 8.1.1 is affected.
- Version 8.1.0 is affected.
- Version 8.0.1 is affected.
- Version 8.0.0 is affected.
- Version 7.88.1 is affected.
- Version 7.88.0 is affected.
- Version 7.87.0 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.