CVE-2025-14017
When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers. Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.
- Affected products
- Debian, Linuxmint, Red Os, Suse Linux Enterprise Server 15 Sp4, Ubuntu, Libcurl, Opensuse Leap 15.6
- Haxx Curl
- < 8.18.0
- Fix
- Available
- CVSS 3.1
- 6.3 MEDIUM
- EPSS
- 0.1% (1th percentile)
- NVD status
- Analyzed
- Published
- 2026-01-08
CVE-2025-14017 at NVD
No indexed exploits for CVE-2025-14017 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-14017 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.