CVE-2025-14819: Haxx Curl
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
When doing TLS related transfers with reused easy or multi handles and altering the `CURLSSLOPT_NO_PARTIALCHAIN` option, libcurl could accidentally reuse a CA store cached in memory for which the partial chain option was reversed. Contrary to the user's wishes and expectations. This could make libcurl find and accept a trust chain that it otherwise would not.
Affected products
- Haxx Curl: from 7.87.0, before 8.18.0 (fixed in 8.18.0)
Published 2026-01-08. Last modified 2026-09-15.