curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection.
A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade curl | Oct 3, 2025 | Sep 12, 2025 |
| Amazon_linux_2023 | — | Upgrade curlUpgrade curl-minimal-debuginfoUpgrade libcurlUpgrade curl-debuginfoUpgrade libcurl-develUpgrade curl-debugsourceUpgrade libcurl-minimalUpgrade libcurl-debuginfoUpgrade libcurl-minimal-debuginfoUpgrade curl-minimal | Jan 12, 2026 | Sep 12, 2025 |
| Debian | — | Upgrade curl | Jul 12, 2026 | Jul 12, 2026 |
| Dell Powerstore Dsa2026115 | — | Upgrade Dell PowerStoreOS to the latest version | Feb 25, 2026 | Feb 24, 2026 |
| Suse | — | Upgrade libcurl-devel-32bitUpgrade curlUpgrade libcurl4-32bitUpgrade libcurl4Upgrade libcurl-devel | Dec 5, 2025 | Sep 11, 2025 |
| Ubuntu | — | Upgrade libcurl4-nss-devUpgrade curlUpgrade libcurl3-gnutlsUpgrade libcurl4t64Upgrade libcurl4-gnutls-devUpgrade libcurl4Upgrade libcurl4-openssl-devUpgrade libcurl3-nssUpgrade libcurl3t64-gnutls | Feb 26, 2026 | Feb 25, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Feb 9, 2026 | Sep 12, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub