CVE-2025-11563

U

RLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.

References
Link Resource
https://curl.se/docs/CVE-2025-11563.html Patch Vendor Advisory
https://curl.se/docs/CVE-2025-11563.json Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/11/04/1 Mailing List Third Party Advisory
https://lists.debian.org/debian-release/2025/11/msg00504.html Mailing List Third Party Advisory Patch
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:curl:wcurl:*:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

History

26 Feb 2026, 20:06

Type Values Removed Values Added
First Time Curl wcurl
Haxx
Curl
Haxx curl
CPE cpe:2.3:a:curl:wcurl:*:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
CWE CWE-22
References () https://curl.se/docs/CVE-2025-11563.html - () https://curl.se/docs/CVE-2025-11563.html - Patch, Vendor Advisory
References () https://curl.se/docs/CVE-2025-11563.json - () https://curl.se/docs/CVE-2025-11563.json - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/11/04/1 - () http://www.openwall.com/lists/oss-security/2025/11/04/1 - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-release/2025/11/msg00504.html - () https://lists.debian.org/debian-release/2025/11/msg00504.html - Mailing List, Third Party Advisory, Patch

25 Feb 2026, 19:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
References
  • () https://lists.debian.org/debian-release/2025/11/msg00504.html -

25 Feb 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 08:16

Updated : 2026-02-26 20:06


NVD link : CVE-2025-11563

Mitre link : CVE-2025-11563

CVE.ORG link : CVE-2025-11563


JSON object : View

Products Affected
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')