KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-01 00:15
Updated : 2026-01-02 16:45
NVD link : CVE-2025-69412
Mitre link : CVE-2025-69412
CVE.ORG link : CVE-2025-69412
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation
