CVE-2025-10148 describes a vulnerability in haxx curl's WebSocket implementation where a fixed 32-bit mask pattern was used for outgoing frames instead of a dynamically updated one, violating specification. This flaw allows a malicious server to induce traffic that could be misinterpreted as genuine HTTP by proxies, leading to cache poisoning and potentially serving malicious content to other users. Rated as Medium severity (CVSS 5.3), it has a low attack complexity and does not require user interaction, though the impact is limited to confidentiality. There is currently no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, but it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.11.0, < 8.16.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
>= 8.11.0, <= 8.11.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 8.11.1, <= 8.11.1CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 8.12.0, <= 8.12.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 8.12.1, <= 8.12.1CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.