CVE-2025-0167

LOW

curl 7.76.0-8.11.0 - Credential Leak via .netrc Default Entry

Title source: llm
STIX 2.1

Description

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.

References (4)

Core 4
Core References
Exploit, Issue Tracking, Third Party Advisory
https://hackerone.com/reports/2917232

Scores

CVSS v3 3.4
EPSS 0.0033
EPSS Percentile 56.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

Status published
Products (16)
haxx/curl 7.76.0 - 8.12.0
netapp/bootstrap_os
netapp/element_software
netapp/h300s_firmware
netapp/h410c_firmware
netapp/h410s_firmware
netapp/h500s_firmware
netapp/h610c_firmware
netapp/h610s_firmware
netapp/h615c_firmware
... and 6 more
Published Feb 05, 2025
Tracked Since Feb 18, 2026