cbcvebase.
CVE-2025-0725
published 2025-02-05

CVE-2025-0725: When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3…

PriorityP341high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
1.26%
68.4th percentile
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

Affected

185 ranges· showing 25
VendorProductVersion rangeFixed in
curlcurl7.10.5 – 7.10.5—
curlcurl7.10.6 – 7.10.6—
curlcurl7.10.7 – 7.10.7—
curlcurl7.10.8 – 7.10.8—
curlcurl7.11.0 – 7.11.0—
curlcurl7.11.1 – 7.11.1—
curlcurl7.11.2 – 7.11.2—
curlcurl7.12.0 – 7.12.0—
curlcurl7.12.1 – 7.12.1—
curlcurl7.12.2 – 7.12.2—
curlcurl7.12.3 – 7.12.3—
curlcurl7.13.0 – 7.13.0—
curlcurl7.13.1 – 7.13.1—
curlcurl7.13.2 – 7.13.2—
curlcurl7.14.0 – 7.14.0—
curlcurl7.14.1 – 7.14.1—
curlcurl7.15.0 – 7.15.0—
curlcurl7.15.1 – 7.15.1—
curlcurl7.15.2 – 7.15.2—
curlcurl7.15.3 – 7.15.3—
curlcurl7.15.4 – 7.15.4—
curlcurl7.15.5 – 7.15.5—
curlcurl7.16.0 – 7.16.0—
curlcurl7.16.1 – 7.16.1—
curlcurl7.16.2 – 7.16.2—

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv7.3HIGH
vendor_debian7.3LOW
vendor_msrc7.3HIGH
vendor_oracle7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.