PT-2025-23788 · Libcurl+6 · Libcurl+6

Z2

·

Published

2025-05-31

·

Updated

2026-05-18

·

CVE-2025-5399

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libcurl versions prior to 8.0.0 Oracle MySQL versions 8.0.0 and earlier Oracle MySQL versions 8.4.0 and earlier Oracle MySQL versions 9.0.0 and earlier
Description A flaw exists in the WebSocket code of libcurl where a malicious server can send a crafted packet, causing libcurl to enter an endless busy-loop. The application has no means to escape this loop other than terminating the thread or process, potentially leading to a denial-of-service (DoS) condition for applications using libcurl. This issue also affects Oracle MySQL through its dependency on libcurl within the Server:Packaging component. Successful exploitation can lead to a hang or frequent crashes of the MySQL Server.
Recommendations libcurl versions prior to 8.0.0: Update to version 8.0.0 or later. Oracle MySQL versions 8.0.0 and earlier: Update to a version later than 8.0.0. Oracle MySQL versions 8.4.0 and earlier: Update to a version later than 8.4.0. Oracle MySQL versions 9.0.0 and earlier: Update to a version later than 9.0.0.

Exploit

Fix

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:15699
ALSA-2025:16046
ALT-PU-2025-7807
BDU:2025-10234
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2025-5399
ECHO-0BD5-994D-5BB9
INFSA-2025_16046
JLSEC-2026-434
OPENSUSE-SU-2025:15213-1
RHSA-2025_16046
SUSE-SU-2025:03198-1
SUSE-SU-2025:20675-1
SUSE-SU-2025_03198-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Mysql Server
Red Hat
Suse
Libcurl