KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 31 Dec 2025 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Kde
Kde messagelib
CPEs cpe:2.3:a:kde:messagelib:*:*:*:*:*:*:*:*
Vendors & Products Kde
Kde messagelib

Wed, 31 Dec 2025 23:30:00 +0000

Type Values Removed Values Added
Description KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-31T23:36:14.430Z

Reserved: 2025-12-31T23:20:55.535Z

Link: CVE-2025-69412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-01T00:15:40.797

Modified: 2026-01-01T00:15:40.797

Link: CVE-2025-69412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses