CVE-2025-0167

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/02/2025
Last modified:
07/03/2025

Description

When asked to use a `.netrc` file for credentials **and** to follow HTTP<br /> redirects, curl could leak the password used for the first host to the<br /> followed-to host under certain circumstances.<br /> <br /> This flaw only manifests itself if the netrc file has a `default` entry that<br /> omits both login and password. A rare circumstance.