PT-2025-47036 · Curl+3 · Curl+3

·

CVE-2025-11563

·

Published

2025-01-01

·

Updated

2026-05-04

CVSS v2.0

4.7

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions curl versions prior to 8.17.0
Description The software is susceptible to a path traversal issue when handling URLs with percent-encoded slashes. This could allow an attacker to access files outside the intended directory.
Recommendations Update to curl version 8.17.0 or later.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03626
CVE-2025-11563
JLSEC-2026-425
OPENSUSE-SU-2025:15757-1
OPENSUSE-SU-2025:20090-1
SUSE-SU-2025:21077-1
SUSE-SU-2025:21145-1
SUSE-SU-2025:21198-1
SUSE-SU-2025:21206-1
SUSE-SU-2025:4180-1
SUSE-SU-2025:4236-1
SUSE-SU-2025:4300-1
SUSE-SU-2025:4309-1
SUSE-SU-2025_4236-1
SUSE-SU-2025_4300-1
USN-8062-1

Affected Products

Linuxmint
Red Os
Ubuntu
Curl