CVE-2025-10148

Summary

curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection.

A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.

Affected Software

VendorProductVersion RangeStatus
curlcurl8.11.0 < 8.14.2affected
curlcurl8.15.0 < 8.16.0affected
curlcurld78e129d50b2d190f1c1bde2ad1f62f02f152db0 < 84db7a9eae8468c0445b15aa806fa7fa806fa0f2affected
curlcurl8.15.0affected
curlcurl8.14.1affected
curlcurl8.14.0affected
curlcurl8.13.0affected
curlcurl8.12.1affected
curlcurl8.12.0affected
curlcurl8.11.1affected
curlcurl8.11.0affected

Weaknesses

  • CWE-340: Generation of Predictable Numbers or Identifiers

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

CVE Program Container

Additional References

References