CVE-2025-4947
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an I
libcurl accidentally skips the certificate verification for QUIC connections when connecting to a host specified as an IP address in the URL. Therefore, it does not detect impostors or man-in-the-middle attacks.
MEDIUM · CVSS 6.5
EPSS 0.00075
Schedule remediation
- Public exploit or PoC is available
Sigma rules7
YARA rules0