CVE-2025-11563

URLs containing percent-encoded slashes (`/` or `\`) can trick wcurl into saving the output file outside of the current directory without the user explicitly asking for it. This flaw only affects the wcurl command line tool.
References
Link Resource
https://curl.se/docs/CVE-2025-11563.html Patch Vendor Advisory
https://curl.se/docs/CVE-2025-11563.json Vendor Advisory
http://www.openwall.com/lists/oss-security/2025/11/04/1 Mailing List Third Party Advisory
https://lists.debian.org/debian-release/2025/11/msg00504.html Mailing List Patch Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:curl:wcurl:*:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

History

17 Jun 2026, 08:30

Type Values Removed Values Added
Summary
  • (es) Las URL que contienen barras codificadas por porcentaje ('/' o '\') pueden engañar a wcurl para que guarde el archivo de salida fuera del directorio actual sin que el usuario lo solicite explícitamente. Este fallo solo afecta a la herramienta de línea de comandos wcurl.
References () https://lists.debian.org/debian-release/2025/11/msg00504.html - Mailing List, Third Party Advisory, Patch () https://lists.debian.org/debian-release/2025/11/msg00504.html - Mailing List, Patch, Third Party Advisory

26 Feb 2026, 20:06

Type Values Removed Values Added
First Time Curl wcurl
Curl
Haxx curl
Haxx
CPE cpe:2.3:a:curl:wcurl:*:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
References () https://curl.se/docs/CVE-2025-11563.html - () https://curl.se/docs/CVE-2025-11563.html - Patch, Vendor Advisory
References () https://curl.se/docs/CVE-2025-11563.json - () https://curl.se/docs/CVE-2025-11563.json - Vendor Advisory
References () http://www.openwall.com/lists/oss-security/2025/11/04/1 - () http://www.openwall.com/lists/oss-security/2025/11/04/1 - Mailing List, Third Party Advisory
References () https://lists.debian.org/debian-release/2025/11/msg00504.html - () https://lists.debian.org/debian-release/2025/11/msg00504.html - Mailing List, Third Party Advisory, Patch
CWE CWE-22

25 Feb 2026, 19:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.6
References
  • () https://lists.debian.org/debian-release/2025/11/msg00504.html -

25 Feb 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 08:16

Updated : 2026-06-17 08:30


NVD link : CVE-2025-11563

Mitre link : CVE-2025-11563

CVE.ORG link : CVE-2025-11563


JSON object : View

Products Affected

haxx

  • curl

curl

  • wcurl
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')