CVE-2025-69412

Name
CVE-2025-69412
Description
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
NVD Severity
low
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://developers.google.com/safe-browsing/v4
cve@mitre.org https://developers.google.com/safe-browsing/v4/lookup-api
cve@mitre.org https://github.com/KDE/messagelib/commit/01adef0482bb3d5c817433db5208620c84a992b3
cve@mitre.org https://github.com/KDE/messagelib/compare/v25.11.80...v25.11.90

Match rules

CPE URI Source package Min version Max version
messagelib == 0 == None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
messagelib edge-community 25.12.1-r1 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 25.12.1-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 25.12.0-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 25.08.3-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 25.08.1-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 25.08.0-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 25.04.2-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 25.04.0-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 24.12.3-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 24.12.2-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 24.12.1-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 24.12.0-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib edge-community 24.08.3-r0 team/kde <bribbers@disroot.org> possibly vulnerable
messagelib 3.23-community 25.08.3-r1 team/kde <bribbers@disroot.org> fixed
messagelib 3.23-community 25.08.3-r0 team/kde <bribbers@disroot.org> possibly vulnerable