KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
https://github.com/KDE/messagelib/compare/v25.11.80...v25.11.90
https://github.com/KDE/messagelib/commit/01adef0482bb3d5c817433db5208620c84a992b3