Sploitus

CVE-2025-4947

No indexed exploits for CVE-2025-4947 yet

libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.

Affected products
Astra Linux, Suse, Libcurl
Haxx Curl
< 8.14.0
CVSS 3.1
6.5 MEDIUM
EPSS
0.2% (16th percentile)
Weakness
CWE-295
NVD status
Analyzed
Published
2025-05-28
CVE-2025-4947 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-4947 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-4947 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.