CVE-2025-0167

EUVD-2025-1518
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
curlCNA
3.4 LOW
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
haxxcurl
7.76.0 ≤
𝑥
< 8.12.0
netappelement_software
-
netappontap_select_deploy_administration_utility
-
netappsolidfire_\&_hci_management_node
-
netappsolidfire_\&_hci_storage_node
-
netappbootstrap_os
-
netapph300s_firmware
-
netapph410c_firmware
-
netapph410s_firmware
-
netapph500s_firmware
-
netapph610c_firmware
-
netapph610s_firmware
-
netapph615c_firmware
-
netapph700s_firmware
-
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
curlcurl
𝑥
≤ 8.11.1
CNA
curlcurl
𝑥
≤ 8.11.0
CNA
curlcurl
𝑥
≤ 8.10.1
CNA
curlcurl
𝑥
≤ 8.10.0
CNA
curlcurl
𝑥
≤ 8.9.1
CNA
curlcurl
𝑥
≤ 8.9.0
CNA
curlcurl
𝑥
≤ 8.8.0
CNA
curlcurl
𝑥
≤ 8.7.1
CNA
curlcurl
𝑥
≤ 8.7.0
CNA
curlcurl
𝑥
≤ 8.6.0
CNA
curlcurl
𝑥
≤ 8.5.0
CNA
curlcurl
𝑥
≤ 8.4.0
CNA
curlcurl
𝑥
≤ 8.3.0
CNA
curlcurl
𝑥
≤ 8.2.1
CNA
curlcurl
𝑥
≤ 8.2.0
CNA
curlcurl
𝑥
≤ 8.1.2
CNA
curlcurl
𝑥
≤ 8.1.1
CNA
curlcurl
𝑥
≤ 8.1.0
CNA
curlcurl
𝑥
≤ 8.0.1
CNA
curlcurl
𝑥
≤ 8.0.0
CNA
curlcurl
𝑥
≤ 7.88.1
CNA
curlcurl
𝑥
≤ 7.88.0
CNA
curlcurl
𝑥
≤ 7.87.0
CNA
curlcurl
𝑥
≤ 7.86.0
CNA
curlcurl
𝑥
≤ 7.85.0
CNA
curlcurl
𝑥
≤ 7.84.0
CNA
curlcurl
𝑥
≤ 7.83.1
CNA
curlcurl
𝑥
≤ 7.83.0
CNA
curlcurl
𝑥
≤ 7.82.0
CNA
curlcurl
𝑥
≤ 7.81.0
CNA
curlcurl
𝑥
≤ 7.80.0
CNA
curlcurl
𝑥
≤ 7.79.1
CNA
curlcurl
𝑥
≤ 7.79.0
CNA
curlcurl
𝑥
≤ 7.78.0
CNA
curlcurl
𝑥
≤ 7.77.0
CNA
curlcurl
𝑥
≤ 7.76.1
CNA
curlcurl
𝑥
≤ 7.76.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
curl
bookworm
7.88.1-10+deb12u14
fixed
bookworm (security)
vulnerable
bullseye
7.74.0-1.3+deb11u13
fixed
bullseye (security)
7.74.0-1.3+deb11u16
fixed
forky
8.20.0-2
fixed
sid
8.20.0-4
fixed
trixie
8.14.1-2+deb13u3
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
curl
suse enterprise desktop 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise desktop 15 SP7
8.6.0-150600.4.21.1
fixed
suse enterprise sap 15 SP4
8.0.1-150400.5.62.1
fixed
suse enterprise sap 15 SP5
8.0.1-150400.5.62.1
fixed
suse enterprise sap 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise sap 15 SP7
8.6.0-150600.4.21.1
fixed
suse enterprise server 12 SP5
8.0.1-11.105.1
fixed
suse enterprise server 15 SP2
7.66.0-150200.4.84.1
fixed
suse enterprise server 15 SP3
7.66.0-150200.4.84.1
fixed
suse enterprise server 15 SP4
8.0.1-150400.5.62.1
fixed
suse enterprise server 15 SP5
8.0.1-150400.5.62.1
fixed
suse enterprise server 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise server 15 SP7
8.6.0-150600.4.21.1
fixed
libcurl-devel
suse enterprise desktop 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise desktop 15 SP7
8.6.0-150600.4.21.1
fixed
suse enterprise sap 15 SP4
8.0.1-150400.5.62.1
fixed
suse enterprise sap 15 SP5
8.0.1-150400.5.62.1
fixed
suse enterprise sap 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise sap 15 SP7
8.6.0-150600.4.21.1
fixed
suse enterprise server 12 SP5
8.0.1-11.105.1
fixed
suse enterprise server 15 SP2
7.66.0-150200.4.84.1
fixed
suse enterprise server 15 SP3
7.66.0-150200.4.84.1
fixed
suse enterprise server 15 SP4
8.0.1-150400.5.62.1
fixed
suse enterprise server 15 SP5
8.0.1-150400.5.62.1
fixed
suse enterprise server 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise server 15 SP7
8.6.0-150600.4.21.1
fixed
libcurl4
suse enterprise desktop 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise desktop 15 SP7
8.6.0-150600.4.21.1
fixed
suse enterprise sap 15 SP4
8.0.1-150400.5.62.1
fixed
suse enterprise sap 15 SP5
8.0.1-150400.5.62.1
fixed
suse enterprise sap 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise sap 15 SP7
8.6.0-150600.4.21.1
fixed
suse enterprise server 12 SP5
8.0.1-11.105.1
fixed
suse enterprise server 15 SP2
7.66.0-150200.4.84.1
fixed
suse enterprise server 15 SP3
7.66.0-150200.4.84.1
fixed
suse enterprise server 15 SP4
8.0.1-150400.5.62.1
fixed
suse enterprise server 15 SP5
8.0.1-150400.5.62.1
fixed
suse enterprise server 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise server 15 SP7
8.6.0-150600.4.21.1
fixed
libcurl4-32bit
suse enterprise desktop 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise desktop 15 SP7
8.6.0-150600.4.21.1
fixed
suse enterprise sap 15 SP4
8.0.1-150400.5.62.1
fixed
suse enterprise sap 15 SP5
8.0.1-150400.5.62.1
fixed
suse enterprise sap 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise sap 15 SP7
8.6.0-150600.4.21.1
fixed
suse enterprise server 12 SP5
8.0.1-11.105.1
fixed
suse enterprise server 15 SP2
7.66.0-150200.4.84.1
fixed
suse enterprise server 15 SP3
7.66.0-150200.4.84.1
fixed
suse enterprise server 15 SP4
8.0.1-150400.5.62.1
fixed
suse enterprise server 15 SP5
8.0.1-150400.5.62.1
fixed
suse enterprise server 15 SP6
8.6.0-150600.4.21.1
fixed
suse enterprise server 15 SP7
8.6.0-150600.4.21.1
fixed