curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection.
A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Oct 3, 2025 | Sep 12, 2025 |
| Amazon_linux_2023 | — | Upgrade curlUpgrade curl-debugsourceUpgrade libcurlUpgrade curl-minimal-debuginfoUpgrade curl-debuginfoUpgrade libcurl-develUpgrade curl-minimalUpgrade libcurl-minimal-debuginfoUpgrade libcurl-debuginfoUpgrade libcurl-minimal | Jan 12, 2026 | Sep 12, 2025 |
| Debian | — | Upgrade curl | Jul 12, 2026 | Jul 12, 2026 |
| Dell Powerstore Dsa2026115 | — | Upgrade Dell PowerStoreOS to the latest version | Feb 25, 2026 | Feb 24, 2026 |
| Suse | — | Upgrade libcurl-develUpgrade libcurl4Upgrade curlUpgrade libcurl4-32bitUpgrade libcurl-devel-32bit | Dec 5, 2025 | Sep 11, 2025 |
| Ubuntu | — | Upgrade libcurl4t64Upgrade libcurl3-gnutlsUpgrade libcurl4-nss-devUpgrade libcurl4-openssl-devUpgrade libcurl4-gnutls-devUpgrade curlUpgrade libcurl4Upgrade libcurl3t64-gnutlsUpgrade libcurl3-nss | Feb 26, 2026 | Feb 25, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Sep 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub