{"api_version":"1","generated_at":"2026-09-15T07:47:02+00:00","cve":"CVE-2025-10148","urls":{"html":"https://cve.report/CVE-2025-10148","api":"https://cve.report/api/cve/CVE-2025-10148.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-10148","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-10148"},"summary":{"title":"predictable WebSocket mask","description":"curl's WebSocket code did not update the 32-bit mask pattern for each new\noutgoing frame as the specification says. Instead it used a fixed mask that\npersisted and was used throughout the entire connection.\n\nA predictable mask pattern allows for a malicious server to induce traffic\nbetween the two communicating parties that could be interpreted by an involved\nproxy (configured or transparent) as genuine, real, HTTP traffic with content\nand thereby poison its cache. That cached poisoned content could then be\nserved to all users of that proxy.","state":"PUBLISHED","assigner":"curl","published_at":"2025-09-12 06:15:40","updated_at":"2026-09-15 07:16:21"},"problem_types":["CWE-340","NVD-CWE-noinfo","CWE-340 Generation of Predictable Numbers or Identifiers"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://curl.se/docs/CVE-2025-10148.html","name":"https://curl.se/docs/CVE-2025-10148.html","refsource":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/10/4","name":"http://www.openwall.com/lists/oss-security/2025/09/10/4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://hackerone.com/reports/3330839","name":"https://hackerone.com/reports/3330839","refsource":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Issue Tracking","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/10/2","name":"http://www.openwall.com/lists/oss-security/2025/09/10/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Patch","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://curl.se/docs/CVE-2025-10148.json","name":"https://curl.se/docs/CVE-2025-10148.json","refsource":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/10/3","name":"http://www.openwall.com/lists/oss-security/2025/09/10/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-10148","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10148","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.11.0 8.14.2 semver","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.15.0 8.16.0 semver","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected d78e129d50b2d190f1c1bde2ad1f62f02f152db0 84db7a9eae8468c0445b15aa806fa7fa806fa0f2 git","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.15.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.14.1","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.14.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.13.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.12.1","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.12.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.11.1","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.11.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Calvin Ruocco (Vector Informatik GmbH)","lang":"en"},{"source":"CNA","value":"Daniel Stenberg","lang":"en"}],"nvd_cpes":[{"cve_year":"2025","cve_id":"10148","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"curl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2025-10148","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-09-12T17:16:46.486840Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-09-12T17:17:12.815Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2025-11-18T20:05:32.822Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2025/09/10/2"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/10/3"},{"url":"http://www.openwall.com/lists/oss-security/2025/09/10/4"}],"title":"CVE Program Container"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"lessThan":"8.14.2","status":"affected","version":"8.11.0","versionType":"semver"},{"lessThan":"8.16.0","status":"affected","version":"8.15.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"curl","repo":"https://github.com/curl/curl.git","vendor":"curl","versions":[{"lessThan":"84db7a9eae8468c0445b15aa806fa7fa806fa0f2","status":"affected","version":"d78e129d50b2d190f1c1bde2ad1f62f02f152db0","versionType":"git"}]},{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"status":"affected","version":"8.15.0"},{"status":"affected","version":"8.14.1"},{"status":"affected","version":"8.14.0"},{"status":"affected","version":"8.13.0"},{"status":"affected","version":"8.12.1"},{"status":"affected","version":"8.12.0"},{"status":"affected","version":"8.11.1"},{"status":"affected","version":"8.11.0"}]}],"credits":[{"lang":"en","type":"finder","value":"Calvin Ruocco (Vector Informatik GmbH)"},{"lang":"en","type":"remediation developer","value":"Daniel Stenberg"}],"descriptions":[{"lang":"en","value":"curl's WebSocket code did not update the 32-bit mask pattern for each new\noutgoing frame as the specification says. Instead it used a fixed mask that\npersisted and was used throughout the entire connection.\n\nA predictable mask pattern allows for a malicious server to induce traffic\nbetween the two communicating parties that could be interpreted by an involved\nproxy (configured or transparent) as genuine, real, HTTP traffic with content\nand thereby poison its cache. That cached poisoned content could then be\nserved to all users of that proxy."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-340","description":"Generation of Predictable Numbers or Identifiers","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-15T06:02:23.283Z","orgId":"2499f714-1537-4658-8207-48ae4bb9eae9","shortName":"curl"},"references":[{"url":"https://curl.se/docs/CVE-2025-10148.json"},{"url":"https://curl.se/docs/CVE-2025-10148.html"},{"url":"https://hackerone.com/reports/3330839"}],"title":"predictable WebSocket mask","x_generator":{"engine":"cvelib 1.8.0"},"x_osv":{"affected":[{"ranges":[{"events":[{"introduced":"8.11.0"},{"fixed":"8.14.2"},{"introduced":"8.15.0"},{"fixed":"8.16.0"}],"type":"SEMVER"},{"events":[{"introduced":"d78e129d50b2d190f1c1bde2ad1f62f02f152db0"},{"fixed":"84db7a9eae8468c0445b15aa806fa7fa806fa0f2"}],"repo":"https://github.com/curl/curl.git","type":"GIT"}],"versions":["8.15.0","8.14.1","8.14.0","8.13.0","8.12.1","8.12.0","8.11.1","8.11.0"]}],"aliases":["CVE-2025-10148"],"credits":[{"name":"Calvin Ruocco (Vector Informatik GmbH)","type":"finder"},{"name":"Daniel Stenberg","type":"remediation developer"}],"database_specific":{"CWE":{"desc":"Generation of Predictable Numbers or Identifiers","id":"CWE-340"},"URL":"https://curl.se/docs/CVE-2025-10148.json","affects":"both","award":{"amount":"505","currency":"USD"},"issue":"https://hackerone.com/reports/3330839","last_affected":"8.15.0","package":"curl","severity":"Low","www":"https://curl.se/docs/CVE-2025-10148.html"},"details":"curl's WebSocket code did not update the 32-bit mask pattern for each new\noutgoing frame as the specification says. Instead it used a fixed mask that\npersisted and was used throughout the entire connection.\n\nA predictable mask pattern allows for a malicious server to induce traffic\nbetween the two communicating parties that could be interpreted by an involved\nproxy (configured or transparent) as genuine, real, HTTP traffic with content\nand thereby poison its cache. That cached poisoned content could then be\nserved to all users of that proxy.","id":"CURL-CVE-2025-10148","modified":"2026-09-07T10:34:51.00Z","published":"2025-09-10T08:00:00.00Z","schema_version":"1.5.0","summary":"predictable WebSocket mask"}}},"cveMetadata":{"assignerOrgId":"2499f714-1537-4658-8207-48ae4bb9eae9","assignerShortName":"curl","cveId":"CVE-2025-10148","datePublished":"2025-09-12T05:10:37.469Z","dateReserved":"2025-09-09T03:45:41.908Z","dateUpdated":"2026-09-15T06:02:23.283Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-09-12 06:15:40","lastModifiedDate":"2026-09-15 07:16:21","problem_types":["CWE-340","NVD-CWE-noinfo","CWE-340 Generation of Predictable Numbers or Identifiers"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-12T17:16:46.486840Z","id":"CVE-2025-10148","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*","versionStartIncluding":"8.11.0","versionEndExcluding":"8.16.0","matchCriteriaId":"A2D88104-00EB-4B8B-88D4-9FCCEF41FA6B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"10148","Ordinal":"1","Title":"predictable WebSocket mask","CVE":"CVE-2025-10148","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"10148","Ordinal":"1","NoteData":"curl's WebSocket code did not update the 32-bit mask pattern for each new\noutgoing frame as the specification says. Instead it used a fixed mask that\npersisted and was used throughout the entire connection.\n\nA predictable mask pattern allows for a malicious server to induce traffic\nbetween the two communicating parties that could be interpreted by an involved\nproxy (configured or transparent) as genuine, real, HTTP traffic with content\nand thereby poison its cache. That cached poisoned content could then be\nserved to all users of that proxy.","Type":"Description","Title":"predictable WebSocket mask"}]}}}