CVE-2025-5399
Due to a mistake in libcurl's WebSocket code, a malicious server can send a
particularly crafted packet which makes libc
Due to a mistake in libcurl's WebSocket code, a malicious server can send a particularly crafted packet which makes libcurl get trapped in an endless busy-loop. There is no other way for the application to escape or exit this loop other than killing the thread/process. This might be used to DoS libcurl-using application.
HIGH · CVSS 7.5
EPSS 0.00566
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules7
YARA rules0