CVE-2025-0167 – Apache Curl HTTP Redirects Password Leak in Netrc File

The following table lists the changes that have been made to the
CVE-2025-0167 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by 2499f714-1537-4658-8207-48ae4bb9eae9

    Feb. 05, 2025

    Action Type Old Value New Value
    Added Description When asked to use a `.netrc` file for credentials **and** to follow HTTP
    redirects, curl could leak the password used for the first host to the
    followed-to host under certain circumstances.

    This flaw only manifests itself if the netrc file has a `default` entry that
    omits both login and password. A rare circumstance.

    Added Reference https://curl.se/docs/CVE-2025-0167.html
    Added Reference https://curl.se/docs/CVE-2025-0167.json
    Added Reference https://hackerone.com/reports/2917232
Share the Post:

Related Posts