{"schema_version":"1.7.5","id":"CURL-CVE-2025-4947","published":"2025-05-28T08:00:00Z","modified":"2026-05-27T02:29:19.655915Z","aliases":["CVE-2025-4947"],"summary":"QUIC certificate check skip with wolfSSL","details":"libcurl accidentally skips the certificate verification for QUIC connections\nwhen connecting to a host specified as an IP address in the URL. Therefore, it\ndoes not detect impostors or man-in-the-middle attacks.","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"8.8.0"},{"fixed":"8.14.0"}]},{"type":"GIT","repo":"https://github.com/curl/curl.git","events":[{"introduced":"4c46e277b2a0c0489de0e0fcb91f315c62f0369c"},{"fixed":"a85f1df4803bbd272905c9e712537b41afeafbd3"}]}],"versions":["8.13.0","8.12.1","8.12.0","8.11.1","8.11.0","8.10.1","8.10.0","8.9.1","8.9.0","8.8.0","curl-8_13_0","curl-8_12_1","curl-8_12_0","curl-8_11_1","curl-8_11_0","curl-8_10_1","curl-8_10_0","curl-8_9_1","curl-8_9_0","curl-8_8_0"],"database_specific":{"source":"https://curl.se/docs/CURL-CVE-2025-4947.json","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["80211781897125907216617466032987610984","68890303834346341213727486246797762367","52142079782883376964682183668234246364","68749118774670511271813411320118219036","257651649534267240063617473881008983603","72459915854897445456226013568529407607","246962167824758465144668491832284230541","148486550461138867129576406502765894046","47205215324501448097833419745667265918","97386622391566701874344023816512674624","265537291877676368672848132467158892736"],"threshold":0.9},"id":"CURL-CVE-2025-4947-43902428","signature_type":"Line","signature_version":"v1","source":"https://github.com/curl/curl.git/commit/a85f1df4803bbd272905c9e712537b41afeafbd3","target":{"file":"lib/vquic/vquic-tls.c"}},{"deprecated":false,"digest":{"function_hash":"56537916447733253337736822579741998455","length":963},"id":"CURL-CVE-2025-4947-74a0efb0","signature_type":"Function","signature_version":"v1","source":"https://github.com/curl/curl.git/commit/a85f1df4803bbd272905c9e712537b41afeafbd3","target":{"file":"lib/vquic/vquic-tls.c","function":"Curl_vquic_tls_verify_peer"}}],"vanir_signatures_modified":"2026-05-27T02:29:19Z"}}],"database_specific":{"CWE":{"desc":"Improper Certificate Validation","id":"CWE-295"},"URL":"https://curl.se/docs/CVE-2025-4947.json","affects":"both","award":{"amount":"2540","currency":"USD"},"issue":"https://hackerone.com/reports/3150884","last_affected":"8.13.0","package":"curl","severity":"Medium","www":"https://curl.se/docs/CVE-2025-4947.html"},"credits":[{"name":"Hiroki Kurosawa","type":"FINDER"},{"name":"Stefan Eissing","type":"REMEDIATION_DEVELOPER"}]}