{"schema_version":"1.7.5","id":"CURL-CVE-2025-5399","published":"2025-06-04T08:00:00Z","modified":"2026-05-27T02:29:29.063535Z","aliases":["CVE-2025-5399"],"summary":"WebSocket endless loop","details":"Due to a mistake in libcurl's WebSocket code, a malicious server can send a\nparticularly crafted packet which makes libcurl get trapped in an endless\nbusy-loop.\n\nThere is no other way for the application to escape or exit this loop other\nthan killing the thread/process.\n\nThis might be used to DoS libcurl-using application.","affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"8.13.0"},{"fixed":"8.14.1"}]},{"type":"GIT","repo":"https://github.com/curl/curl.git","events":[{"introduced":"3588df9478d7c27046b34cdb510728a26bedabc7"},{"fixed":"d1145df24de8f80e6b167fbc4f28b86bcd0c6832"}]}],"versions":["8.14.0","8.13.0","curl-8_14_0","curl-8_13_0"],"database_specific":{"source":"https://curl.se/docs/CURL-CVE-2025-5399.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"246136244445171702857622217714330817191","length":3224},"id":"CURL-CVE-2025-5399-5c67c32b","signature_type":"Function","signature_version":"v1","source":"https://github.com/curl/curl.git/commit/d1145df24de8f80e6b167fbc4f28b86bcd0c6832","target":{"file":"lib/ws.c","function":"curl_ws_send"}},{"deprecated":false,"digest":{"line_hashes":["205927081312732682779716038169572163720","200262896965368108989613347175457420328","191061302736480628505507033467536312329","305720063265502571742731976555669608845"],"threshold":0.9},"id":"CURL-CVE-2025-5399-7940916e","signature_type":"Line","signature_version":"v1","source":"https://github.com/curl/curl.git/commit/d1145df24de8f80e6b167fbc4f28b86bcd0c6832","target":{"file":"lib/ws.c"}}],"vanir_signatures_modified":"2026-05-27T02:29:29Z"}}],"database_specific":{"CWE":{"desc":"Loop with Unreachable Exit Condition ('Infinite Loop')","id":"CWE-835"},"URL":"https://curl.se/docs/CVE-2025-5399.json","affects":"lib","award":{"amount":"505","currency":"USD"},"issue":"https://hackerone.com/reports/3168039","last_affected":"8.14.0","package":"curl","severity":"Low","www":"https://curl.se/docs/CVE-2025-5399.html"},"credits":[{"name":"z2_ on hackerone","type":"FINDER"},{"name":"z2_ on hackerone","type":"REMEDIATION_DEVELOPER"}]}