KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 02 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 31 Dec 2025 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Kde
Kde messagelib
CPEs cpe:2.3:a:kde:messagelib:*:*:*:*:*:*:*:*
Vendors & Products Kde
Kde messagelib

Wed, 31 Dec 2025 23:30:00 +0000

Type Values Removed Values Added
Description KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-02T13:45:18.339Z

Reserved: 2025-12-31T23:20:55.535Z

Link: CVE-2025-69412

cve-icon Vulnrichment

Updated: 2026-01-02T13:45:08.868Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-01T00:15:40.797

Modified: 2026-01-02T16:45:26.640

Link: CVE-2025-69412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses