CVE-2025-69412: Kde Messagelib

Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.

KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.

Affected products

  • Kde Messagelib: before 25.11.90 (fixed in 25.11.90)

Published 2026-01-01. Last modified 2026-06-17.