CVE-2025-13034

Summary

When using CURLOPT_PINNEDPUBLICKEY option with libcurl or --pinnedpubkey with the curl tool, curl should check the public key of the server certificate to verify the peer.

This check was skipped in a certain condition that would then make curl allow the connection without performing the proper check, thus not noticing a possible impostor. To skip this check, the connection had to be done with QUIC with ngtcp2 built to use GnuTLS and the user had to explicitly disable the standard certificate verification.

Affected Software

VendorProductVersion RangeStatus
curlcurl8.8.0 < 8.14.2affected
curlcurl8.15.0 < 8.16.1affected
curlcurl8.17.0 < 8.18.0affected
curlcurl3210101088dfa3d6a125d213226b092f2f866722 < 3d91ca8cdb3b434226e743946d428b4dd3acf2c9affected
curlcurl8.17.0affected
curlcurl8.16.0affected
curlcurl8.15.0affected
curlcurl8.14.1affected
curlcurl8.14.0affected
curlcurl8.13.0affected
curlcurl8.12.1affected
curlcurl8.12.0affected
curlcurl8.11.1affected
curlcurl8.11.0affected
curlcurl8.10.1affected
curlcurl8.10.0affected
curlcurl8.9.1affected
curlcurl8.9.0affected
curlcurl8.8.0affected

Weaknesses

  • CWE-295: Improper Certificate Validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References