PT-2025-54485 · Gnutls+6 · Gnutls+6

Daniel Stenberg

+1

·

Published

2025-01-01

·

Updated

2026-05-04

·

CVE-2025-13034

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions libcurl (affected versions not specified)
Description When utilizing the CURLOPT PINNEDPUBLICKEY option in libcurl or the --pinnedpubkey option with the curl tool, the software should verify the server certificate's public key to confirm the peer's identity. A condition existed where this check was bypassed, allowing connections without proper verification and potentially enabling connections to an impostor. This occurred specifically when using QUIC with ngtcp2 built to use GnuTLS, and when standard certificate verification was explicitly disabled. The vulnerable component is the public key verification process when using pinned public keys.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2025-13034
JLSEC-2026-426
MGASA-2026-0003
RHSA-2026:6893
USN-8062-1

Affected Products

Debian
Gnutls
Linuxmint
Ubuntu
Curl
Libcurl
Ngtcp2