CVE-2025-0167

When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.4 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
curlCNA
---
---
CISA-ADPADP
3.4 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
haxxcurl
7.76.0 ≤
𝑥
< 8.12.0
netappelement_software
-
netappontap_select_deploy_administration_utility
-
netappsolidfire_\&_hci_management_node
-
netappsolidfire_\&_hci_storage_node
-
netappbootstrap_os
-
netapph300s_firmware
-
netapph410c_firmware
-
netapph410s_firmware
-
netapph500s_firmware
-
netapph610c_firmware
-
netapph610s_firmware
-
netapph615c_firmware
-
netapph700s_firmware
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
curl
bullseye
7.74.0-1.3+deb11u13
not-affected
bullseye (security)
7.74.0-1.3+deb11u15
fixed
bookworm
7.88.1-10+deb12u12
fixed
bookworm (security)
vulnerable
trixie
8.14.1-2
fixed
forky
8.15.0-1
fixed
sid
8.16.0~rc2-2
fixed