Bug 2426564 (CVE-2025-69412) - CVE-2025-69412 messagelib: messagelib: Spoofing of threat data due to ignored SSL errors
Summary: CVE-2025-69412 messagelib: messagelib: Spoofing of threat data due to ignored...
Keywords:
Status: NEW
Alias: CVE-2025-69412
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2426619 2426620 2426621 2426622 2426623 2426624 2426625 2426628 2426629
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-01 00:01 UTC by OSIDB Bzimport
Modified: 2026-01-01 11:37 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-01-01 00:01:18 UTC
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.


Note You need to log in before you can comment on or make changes to this bug.