predictable WebSocket mask
Summary
| CVE | CVE-2025-10148 |
|---|---|
| State | PUBLISHED |
| Assigner | curl |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-09-12 06:15:40 UTC |
| Updated | 2026-09-15 07:16:21 UTC |
| Description | curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Problem Types: CWE-340 | NVD-CWE-noinfo | CWE-340 Generation of Predictable Numbers or Identifiers
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Curl | Curl | affected 8.11.0 8.14.2 semver | Not specified |
| CNA | Curl | Curl | affected 8.15.0 8.16.0 semver | Not specified |
| CNA | Curl | Curl | affected d78e129d50b2d190f1c1bde2ad1f62f02f152db0 84db7a9eae8468c0445b15aa806fa7fa806fa0f2 git | Not specified |
| CNA | Curl | Curl | affected 8.15.0 | Not specified |
| CNA | Curl | Curl | affected 8.14.1 | Not specified |
| CNA | Curl | Curl | affected 8.14.0 | Not specified |
| CNA | Curl | Curl | affected 8.13.0 | Not specified |
| CNA | Curl | Curl | affected 8.12.1 | Not specified |
| CNA | Curl | Curl | affected 8.12.0 | Not specified |
| CNA | Curl | Curl | affected 8.11.1 | Not specified |
| CNA | Curl | Curl | affected 8.11.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| curl.se/docs/CVE-2025-10148.html | 2499f714-1537-4658-8207-48ae4bb9eae9 | curl.se | Patch, Vendor Advisory |
| www.openwall.com/lists/oss-security/2025/09/10/4 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| hackerone.com/reports/3330839 | 2499f714-1537-4658-8207-48ae4bb9eae9 | hackerone.com | Issue Tracking, Third Party Advisory |
| www.openwall.com/lists/oss-security/2025/09/10/2 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| curl.se/docs/CVE-2025-10148.json | 2499f714-1537-4658-8207-48ae4bb9eae9 | curl.se | Vendor Advisory |
| www.openwall.com/lists/oss-security/2025/09/10/3 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Calvin Ruocco (Vector Informatik GmbH) (en)
CNA: Daniel Stenberg (en)
There are currently no legacy QID mappings associated with this CVE.