---
schema_version: '1.0'
id: security-20260705-25786f
url: https://osv.dev/vulnerability/CURL-CVE-2025-14017
url_hash: 25786f90b7eeb52b3f72e96ecd94de1303031d41ee26febad3ec056894f2a6ec
canonical_url: https://osv.dev/vulnerability/CURL-CVE-2025-14017
source: osv:osv
category: security/library
category_raw: cve/library
region: null
tags:
- cve
- CVE-2025-14017
- CURL-CVE-2025-14017
- severity:Medium
- https://github.com/curl/curl
- GIT
lang: en
published_at: '2026-01-07T08:00:00Z'
fetched_at: '2026-07-05T15:34:34Z'
updated_at: '2026-07-05T15:37:03Z'
status: published
content_hash: 6628627c18aa4a107301cd3f2b0c75140e3c322c9d0d8f25e09a837e611e7048
license_note: full
summary: broken TLS options for threaded LDAPS
summary_source: rss
summary_en: broken TLS options for threaded LDAPS
entities:
- name: GitHub
  type: organization
- name: FORZA STYLE
  type: organization
key_facts: []
related: []
related_auto:
- name: Anonymous
  type: organization
  weight: 1.0
- name: AirPods
  type: artifact
  weight: 1.0
- name: Claude Code
  type: artifact
  weight: 1.0
- name: セッション漏洩
  type: event
  weight: 1.0
- name: local-llm
  type: content
  weight: 1.0
title: 'CVE-2025-14017: broken TLS options for threaded LDAPS'
---

# CVE-2025-14017: broken TLS options for threaded LDAPS

## TL;DR
broken TLS options for threaded LDAPS

## Key Points
- cve / CVE-2025-14017 / CURL-CVE-2025-14017 / severity:Medium / https://github.com/curl/curl / GIT

## Details
**Severity:** Medium
**Advisory:** CURL-CVE-2025-14017 (CVE-2025-14017)

**Affected (your watchlist):**
- `GIT:https://github.com/curl/curl` curl-8_9_1 → no fixed version listed [mac]

**Details:**
When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl,
changing TLS options in one thread would inadvertently change them globally
and therefore possibly also affect other concurrently setup transfers.

Disabling certificate verification for a specific transfer could
unintentionally disable the feature for other threads as well.

_Data: OSV.dev (upstream: osv) — https://osv.dev/vulnerability/CURL-CVE-2025-14017_

## Source
元記事: [CVE-2025-14017: broken TLS options for threaded LDAPS](https://osv.dev/vulnerability/CURL-CVE-2025-14017) — published 2026-01-07T08:00:00Z
