Critical
Low
Medium
CVE-2025-10148
Overview
curl's websocket code did not update the 32 bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traffic between the two ...
Critical
Low
Medium
No items found.