KDE messagelib before 25.11.90 ignores SSL errors for...
Low severity
Unreviewed
Published
Jan 1, 2026
to the GitHub Advisory Database
•
Updated Jan 1, 2026
Description
Published by the National Vulnerability Database
Jan 1, 2026
Published to the GitHub Advisory Database
Jan 1, 2026
Last updated
Jan 1, 2026
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
References