THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-10148 (MEDIUM 5.3) — curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traff

[NVD] CVE-2025-10148 (MEDIUM 5.3) — curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection. A predictable mask pattern allows for a malicious server to induce traff

lownvdPublished 2025-09-12

CVE-2025-10148 CVSS: 5.3 MEDIUM Published: 2025-09-12T06:15:40.020

curl's WebSocket code did not update the 32-bit mask pattern for each new outgoing frame as the specification says. Instead it used a fixed mask that persisted and was used throughout the entire connection.

A predictable mask pattern allows for a malicious server to induce traffic between the two communicating parties that could

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-10148