Path traversal in cURL and wcurl - CVE-2025-11563

 

Path traversal in cURL and wcurl - CVE-2025-11563

Published: November 24, 2025


Vulnerability identifier: #VU118723
CSH Severity:
CVSS v4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-11563
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing percent-encoded slashes (/ or \\) in wcurl. A remote attacker can trick the application into saving the output file outside of the current directory without the user explicitly asking for it.


Affected software

cURL
wcurl
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Ubuntu
Basesystem Module
openSUSE Leap
curl (Ubuntu package)
libcurl4
curl-debugsource
curl-debuginfo
libcurl4-debuginfo
curl
libcurl-devel
curl-mini-debugsource
libcurl-mini4
libcurl-mini4-debuginfo
curl-zsh-completion
libcurl-devel-doc
curl-fish-completion
libcurl4-32bit-debuginfo
libcurl4-32bit
libcurl-devel-32bit
libcurl4-64bit-debuginfo
libcurl4-64bit
libcurl-devel-64bit

How to mitigate CVE-2025-11563

Install updates from vendor's website.

cURL - update to 8.17.0
wcurl - update to 2025.11.04
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm19, 7.47.0-1ubuntu2.19+esm15, 7.58.0-2ubuntu3.24+esm7, 7.68.0-1ubuntu2.25+esm2, 7.81.0-1ubuntu1.22, 8.5.0-2ubuntu10.7, 8.14.1-2ubuntu1.1
libcurl4 - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
curl-debugsource - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
curl-debuginfo - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
libcurl4-debuginfo - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
curl - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
libcurl-devel - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
curl-mini-debugsource - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl-mini4 - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl-mini4-debuginfo - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
curl-zsh-completion - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl-devel-doc - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
curl-fish-completion - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl4-32bit-debuginfo - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
libcurl4-32bit - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
libcurl-devel-32bit - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl4-64bit-debuginfo - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl4-64bit - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl-devel-64bit - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1

External References

Related Security Bulletins