CVE-2025-0167
published 2025-02-05CVE-2025-0167: When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to…
PriorityP415low3.4CVSS 3.1
AVNACHPRNUIRSCCLINAN
EPSS
0.66%
47.9th percentile
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
Affected
64 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 7.76.0 – 7.76.0 | — |
| curl | curl | 7.76.1 – 7.76.1 | — |
| curl | curl | 7.77.0 – 7.77.0 | — |
| curl | curl | 7.78.0 – 7.78.0 | — |
| curl | curl | 7.79.0 – 7.79.0 | — |
| curl | curl | 7.79.1 – 7.79.1 | — |
| curl | curl | 7.80.0 – 7.80.0 | — |
| curl | curl | 7.81.0 – 7.81.0 | — |
| curl | curl | 7.82.0 – 7.82.0 | — |
| curl | curl | 7.83.0 – 7.83.0 | — |
| curl | curl | 7.83.1 – 7.83.1 | — |
| curl | curl | 7.84.0 – 7.84.0 | — |
| curl | curl | 7.85.0 – 7.85.0 | — |
| curl | curl | 7.86.0 – 7.86.0 | — |
| curl | curl | 7.87.0 – 7.87.0 | — |
| curl | curl | 7.88.0 – 7.88.0 | — |
| curl | curl | 7.88.1 – 7.88.1 | — |
| curl | curl | 8.0.0 – 8.0.0 | — |
| curl | curl | 8.0.1 – 8.0.1 | — |
| curl | curl | 8.1.0 – 8.1.0 | — |
| curl | curl | 8.1.1 – 8.1.1 | — |
| curl | curl | 8.1.2 – 8.1.2 | — |
| curl | curl | 8.10.0 – 8.10.0 | — |
| curl | curl | 8.10.1 – 8.10.1 | — |
| curl | curl | 8.11.0 – 8.11.0 | — |
CVSS provenance
nvdv3.13.4LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
osv3.4LOW
vendor_debian3.4LOW
vendor_msrc3.4LOW
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
curl vulnerabilities
osv·2026-03-11·CVSS 3.4
CVE-2026-1965 [LOW] curl vulnerabilities
curl vulnerabilities
Zhicheng Chen discovered that curl could incorrectly reuse the wrong
connection for Negotiate-authenticated HTTP or HTTPS requests. This could
result in the use of credentials from a different connection, contrary to
expectations. (CVE-2026-1965)
It was discovered that curl incorrectly leaked OAuth2 bearer tokens when
following a redirect. This could result in tokens being sent to the wrong
host, contrary to expectations. (CVE-2026-3783)
Muhamad Arga Reksapati discovered that curl incorrectly reused existing
HTTP proxy connections even if the request used different credentials. This
could result in the use of incorrect credentials, contrary to expectations.
(CVE-2026-3784)
Daniel Wade discovered that curl incorrectly handled certain memory
operations when doing a s
GHSA
GHSA-c42g-rmxf-64ch: When asked to use a `
ghsa_unreviewed·2025-02-05
CVE-2025-0167 [LOW] GHSA-c42g-rmxf-64ch: When asked to use a `
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
OSV
CVE-2025-0167: When asked to use a `
osv·2025-02-05·CVSS 3.4
CVE-2025-0167 [LOW] CVE-2025-0167: When asked to use a `
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
OSV
CVE-2025-0167: When asked to use a `
osv·2025-02-05·CVSS 3.4
CVE-2025-0167 [LOW] CVE-2025-0167: When asked to use a `
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-03-11·CVSS 3.4
CVE-2025-0167 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Zhicheng Chen discovered that curl could incorrectly reuse the wrong
connection for Negotiate-authenticated HTTP or HTTPS requests. This could
result in the use of credentials from a different connection, contrary to
expectations. (CVE-2026-1965)
It was discovered that curl incorrectly leaked OAuth2 bearer tokens when
following a redirect. This could result in tokens being sent to the wrong
host, contrary to expectations. (CVE-2026-3783)
Muhamad Arga Reksapati discovered that curl incorrectly reused existing
HTTP proxy connections even if the request used different credentials. This
could result in the use of incorrect credentials, contrary to expectations.
(CVE-2026-3784)
Daniel Wade discovered that curl
Microsoft
netrc and default credential leak
vendor_msrc·2025-02-11·CVSS 3.4
CVE-2025-0167 [LOW] netrc and default credential leak
netrc and default credential leak
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
curl: curl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azu
Debian
CVE-2025-0167: curl - When asked to use a `.netrc` file for credentials **and** to follow HTTP redirec...
vendor_debian·2025·CVSS 3.4
CVE-2025-0167 [LOW] CVE-2025-0167: curl - When asked to use a `.netrc` file for credentials **and** to follow HTTP redirec...
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
Scope: local
bookworm: resolved (fixed in 7.88.1-10+deb12u11)
bullseye: resolved
forky: resolved (fixed in 8.12.0+git20250209.89ed161+ds-1)
sid: resolved (fixed in 8.12.0+git20250209.89ed161+ds-1)
trixie: resolved (fixed in 8.12.0+git20250209.89ed161+ds-1)
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2026-3783: token leak with redirect and netrc
hackerone·2026-03-11·CVSS 5.3
CVE-2026-3783 [MEDIUM] CVE-2026-3783: token leak with redirect and netrc
CVE-2026-3783: token leak with redirect and netrc
##Summary
When `--oauth2-bearer` is used with `--netrc` and curl follows a redirect, the bearer token leaks to the redirect target. The netrc bypass at `http.c:822` skips `Curl_auth_allowed_to_host()`, allowing the token through. This is an incomplete fix for CVE-2025-14524 — the Dec 2025 SASL fix patched `curl_sasl.c` but missed the HTTP bearer path.
This is an incomplete fix for the same vulnerability class as CVE-2025-14524. The Dec 2025 SASL bearer fix (commit `1a822275d3`, PR #19933) patched `lib/curl_sasl.c` but left the HTTP bearer path at `lib/http.c:704-714` unprotected.
## Version
curl 8.10.1 (confirmed), also present in current master `d9c2c64337`. All versions supporting `--oauth2-bearer` with `--netrc` are affected.
**The n
HackerOne
CVE-2025-0167: netrc and default credential leak
hackerone·2025-02-07·CVSS 3.4
CVE-2025-0167 [LOW] CVE-2025-0167: netrc and default credential leak
CVE-2025-0167: netrc and default credential leak
## Summary:
The fix for CVE-2024-11053 seems to be incomplete.The information leak problem could be reproduced again if use netrc in step1.
## Affected version
all
## Steps To Reproduce:
1. Adapt test479 to use netrc like below(both of user and password are not provided for b.com):
machine a.com
login alice
password alicespassword
default
2.Run test479
3. The test would fail because alice and alicepassword were used for b.com.
I used the latest version curl 8.11.1 but the problem still exists.I'm not sure if this is expected.Please point it out if i'm wrong.
## Impact
## Summary:
Sensitive information disclosure.
Bugzilla
CVE-2025-0167 libcurl: Libcurl .netrc Credential Leak via Redirect
bugzilla·2025-02-05·CVSS 3.4
CVE-2025-0167 [LOW] CVE-2025-0167 libcurl: Libcurl .netrc Credential Leak via Redirect
CVE-2025-0167 libcurl: Libcurl .netrc Credential Leak via Redirect
When asked to use a `.netrc` file for credentials **and** to follow HTTP
redirects, curl could leak the password used for the first host to the
followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that
omits both login and password. A rare circumstance.
2025-02-05
Published