CVE-2025-0167

EUVD-2025-1518
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.4 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
CISA-ADPADP
3.4 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
Affected Products (NVD)
VendorProductVersion
haxxcurl
7.76.0 ≤
𝑥
< 8.12.0
netappelement_software
-
netappontap_select_deploy_administration_utility
-
netappsolidfire_\&_hci_management_node
-
netappsolidfire_\&_hci_storage_node
-
netappbootstrap_os
-
netapph300s_firmware
-
netapph410c_firmware
-
netapph410s_firmware
-
netapph500s_firmware
-
netapph610c_firmware
-
netapph610s_firmware
-
netapph615c_firmware
-
netapph700s_firmware
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
curl
bookworm
7.88.1-10+deb12u14
fixed
bookworm (security)
vulnerable
bullseye
7.74.0-1.3+deb11u13
not-affected
bullseye (security)
7.74.0-1.3+deb11u16
fixed
forky
8.18.0-2
fixed
sid
8.19.0~rc3-1
fixed
trixie
8.14.1-2+deb13u2
fixed