KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 02 Jan 2026 23:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Jan 2026 08:45:00 +0900

Type Values Removed Values Added
First Time appeared Kde
Kde messagelib
CPEs cpe:2.3:a:kde:messagelib:*:*:*:*:*:*:*:*
Vendors & Products Kde
Kde messagelib

Thu, 01 Jan 2026 08:30:00 +0900

Type Values Removed Values Added
Description KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-02T13:45:18.339Z

Reserved: 2025-12-31T23:20:55.535Z

Link: CVE-2025-69412

cve-icon Vulnrichment

Updated: 2026-01-02T13:45:08.868Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-01T00:15:40.797

Modified: 2026-01-02T16:45:26.640

Link: CVE-2025-69412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses