CVE-2025-0167
LOWcurl 7.76.0-8.11.0 - Credential Leak via .netrc Default Entry
Title source: llmDescription
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
References (4)
Core 4
Core References
Vendor Advisory
https://curl.se/docs/CVE-2025-0167.html
Vendor Advisory
https://curl.se/docs/CVE-2025-0167.json
Exploit, Issue Tracking, Third Party Advisory
https://hackerone.com/reports/2917232
Third Party Advisory
https://security.netapp.com/advisory/ntap-20250306-0008/
Scores
CVSS v3
3.4
EPSS
0.0033
EPSS Percentile
56.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
Status
published
Products (16)
haxx/curl
7.76.0 - 8.12.0
netapp/bootstrap_os
netapp/element_software
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h610c_firmware
netapp/h610s_firmware
netapp/h615c_firmware
... and 6 more
Published
Feb 05, 2025
Tracked Since
Feb 18, 2026