{"api_version":"1","generated_at":"2026-09-15T07:47:54+00:00","cve":"CVE-2025-13034","urls":{"html":"https://cve.report/CVE-2025-13034","api":"https://cve.report/api/cve/CVE-2025-13034.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-13034","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-13034"},"summary":{"title":"No QUIC certificate pinning with GnuTLS","description":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.","state":"PUBLISHED","assigner":"curl","published_at":"2026-01-08 10:15:45","updated_at":"2026-09-15 07:16:23"},"problem_types":["CWE-295","CWE-295 Improper Certificate Validation","CWE-295 CWE-295 Improper Certificate Validation"],"metrics":[{"version":"3.1","source":"ADP","type":"DECLARED","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}}],"references":[{"url":"https://curl.se/docs/CVE-2025-13034.json","name":"https://curl.se/docs/CVE-2025-13034.json","refsource":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://curl.se/docs/CVE-2025-13034.html","name":"https://curl.se/docs/CVE-2025-13034.html","refsource":"2499f714-1537-4658-8207-48ae4bb9eae9","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-13034","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13034","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.8.0 8.14.2 semver","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.15.0 8.16.1 semver","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.17.0 8.18.0 semver","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 3210101088dfa3d6a125d213226b092f2f866722 3d91ca8cdb3b434226e743946d428b4dd3acf2c9 git","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.17.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.16.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.15.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.14.1","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.14.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.13.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.12.1","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.12.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.11.1","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.11.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.10.1","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.10.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.9.1","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.9.0","platforms":[]},{"source":"CNA","vendor":"curl","product":"curl","version":"affected 8.8.0","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Stanislav Fort (Aisle Research)","lang":"en"},{"source":"CNA","value":"Daniel Stenberg","lang":"en"}],"nvd_cpes":[{"cve_year":"2025","cve_id":"13034","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"haxx","cpe5":"curl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2025-13034","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-01-08T14:56:11.206224Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-295","description":"CWE-295 Improper Certificate Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-01-08T14:58:20.565Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"lessThan":"8.14.2","status":"affected","version":"8.8.0","versionType":"semver"},{"lessThan":"8.16.1","status":"affected","version":"8.15.0","versionType":"semver"},{"lessThan":"8.18.0","status":"affected","version":"8.17.0","versionType":"semver"}]},{"defaultStatus":"unaffected","product":"curl","repo":"https://github.com/curl/curl.git","vendor":"curl","versions":[{"lessThan":"3d91ca8cdb3b434226e743946d428b4dd3acf2c9","status":"affected","version":"3210101088dfa3d6a125d213226b092f2f866722","versionType":"git"}]},{"defaultStatus":"unaffected","product":"curl","vendor":"curl","versions":[{"status":"affected","version":"8.17.0"},{"status":"affected","version":"8.16.0"},{"status":"affected","version":"8.15.0"},{"status":"affected","version":"8.14.1"},{"status":"affected","version":"8.14.0"},{"status":"affected","version":"8.13.0"},{"status":"affected","version":"8.12.1"},{"status":"affected","version":"8.12.0"},{"status":"affected","version":"8.11.1"},{"status":"affected","version":"8.11.0"},{"status":"affected","version":"8.10.1"},{"status":"affected","version":"8.10.0"},{"status":"affected","version":"8.9.1"},{"status":"affected","version":"8.9.0"},{"status":"affected","version":"8.8.0"}]}],"credits":[{"lang":"en","type":"finder","value":"Stanislav Fort (Aisle Research)"},{"lang":"en","type":"remediation developer","value":"Daniel Stenberg"}],"descriptions":[{"lang":"en","value":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification."}],"problemTypes":[{"descriptions":[{"cweId":"CWE-295","description":"Improper Certificate Validation","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-15T06:02:26.327Z","orgId":"2499f714-1537-4658-8207-48ae4bb9eae9","shortName":"curl"},"references":[{"url":"https://curl.se/docs/CVE-2025-13034.json"},{"url":"https://curl.se/docs/CVE-2025-13034.html"}],"title":"No QUIC certificate pinning with GnuTLS","x_generator":{"engine":"cvelib 1.8.0"},"x_osv":{"affected":[{"ranges":[{"events":[{"introduced":"8.8.0"},{"fixed":"8.14.2"},{"introduced":"8.15.0"},{"fixed":"8.16.1"},{"introduced":"8.17.0"},{"fixed":"8.18.0"}],"type":"SEMVER"},{"events":[{"introduced":"3210101088dfa3d6a125d213226b092f2f866722"},{"fixed":"3d91ca8cdb3b434226e743946d428b4dd3acf2c9"}],"repo":"https://github.com/curl/curl.git","type":"GIT"}],"versions":["8.17.0","8.16.0","8.15.0","8.14.1","8.14.0","8.13.0","8.12.1","8.12.0","8.11.1","8.11.0","8.10.1","8.10.0","8.9.1","8.9.0","8.8.0"]}],"aliases":["CVE-2025-13034"],"credits":[{"name":"Stanislav Fort (Aisle Research)","type":"finder"},{"name":"Daniel Stenberg","type":"remediation developer"}],"database_specific":{"CWE":{"desc":"Improper Certificate Validation","id":"CWE-295"},"URL":"https://curl.se/docs/CVE-2025-13034.json","affects":"both","award":{"amount":"2540","currency":"USD"},"last_affected":"8.17.0","package":"curl","severity":"Medium","www":"https://curl.se/docs/CVE-2025-13034.html"},"details":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.","id":"CURL-CVE-2025-13034","modified":"2026-09-07T10:34:51.00Z","published":"2026-01-07T08:00:00.00Z","schema_version":"1.5.0","summary":"No QUIC certificate pinning with GnuTLS"}}},"cveMetadata":{"assignerOrgId":"2499f714-1537-4658-8207-48ae4bb9eae9","assignerShortName":"curl","cveId":"CVE-2025-13034","datePublished":"2026-01-08T10:00:25.773Z","dateReserved":"2025-11-11T16:52:22.121Z","dateUpdated":"2026-09-15T06:02:26.327Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-01-08 10:15:45","lastModifiedDate":"2026-09-15 07:16:23","problem_types":["CWE-295","CWE-295 Improper Certificate Validation","CWE-295 CWE-295 Improper Certificate Validation"],"metrics":{"cvssMetricV31":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-08T14:56:11.206224Z","id":"CVE-2025-13034","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*","versionStartIncluding":"8.8.0","versionEndExcluding":"8.18.0","matchCriteriaId":"E6152C75-3784-4E17-A770-4585D1FD80C4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"13034","Ordinal":"1","Title":"No QUIC certificate pinning with GnuTLS","CVE":"CVE-2025-13034","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"13034","Ordinal":"1","NoteData":"When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or `--pinnedpubkey`\nwith the curl tool, curl should check the public key of the server certificate\nto verify the peer.\n\nThis check was skipped in a certain condition that would then make curl allow\nthe connection without performing the proper check, thus not noticing a\npossible impostor. To skip this check, the connection had to be done with QUIC\nwith ngtcp2 built to use GnuTLS and the user had to explicitly disable the\nstandard certificate verification.","Type":"Description","Title":"No QUIC certificate pinning with GnuTLS"}]}}}