Path traversal in cURL and wcurl - CVE-2025-11563
Published: November 24, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing percent-encoded slashes (/ or \\) in wcurl. A remote attacker can trick the application into saving the output file outside of the current directory without the user explicitly asking for it.
Affected software
wcurl
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Ubuntu
Basesystem Module
openSUSE Leap
curl (Ubuntu package)
libcurl4
curl-debugsource
curl-debuginfo
libcurl4-debuginfo
curl
libcurl-devel
curl-mini-debugsource
libcurl-mini4
libcurl-mini4-debuginfo
curl-zsh-completion
libcurl-devel-doc
curl-fish-completion
libcurl4-32bit-debuginfo
libcurl4-32bit
libcurl-devel-32bit
libcurl4-64bit-debuginfo
libcurl4-64bit
libcurl-devel-64bit
How to mitigate CVE-2025-11563
wcurl - update to 2025.11.04
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm19, 7.47.0-1ubuntu2.19+esm15, 7.58.0-2ubuntu3.24+esm7, 7.68.0-1ubuntu2.25+esm2, 7.81.0-1ubuntu1.22, 8.5.0-2ubuntu10.7, 8.14.1-2ubuntu1.1
libcurl4 - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
curl-debugsource - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
curl-debuginfo - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
libcurl4-debuginfo - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
curl - addressed in versions 8.14.1-150200.4.94.1, 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
libcurl-devel - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
curl-mini-debugsource - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl-mini4 - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl-mini4-debuginfo - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
curl-zsh-completion - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl-devel-doc - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
curl-fish-completion - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl4-32bit-debuginfo - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
libcurl4-32bit - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1, 8.14.1-150700.7.5.1
libcurl-devel-32bit - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl4-64bit-debuginfo - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl4-64bit - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1
libcurl-devel-64bit - addressed in versions 8.14.1-150400.5.72.1, 8.14.1-150600.4.31.1