{"id":"CURL-CVE-2025-0167","summary":"netrc and default credential leak","details":"When asked to use a `.netrc` file for credentials **and** to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has a `default` entry that\nomits both login and password. A rare circumstance.","aliases":["CVE-2025-0167"],"modified":"2026-05-29T05:40:22.369582Z","published":"2025-02-05T08:00:00Z","database_specific":{"affects":"both","package":"curl","severity":"Low","CWE":{"desc":"Exposure of Sensitive Information to an Unauthorized Actor","id":"CWE-200"},"award":{"amount":"505","currency":"USD"},"issue":"https://hackerone.com/reports/2917232","last_affected":"8.11.1","www":"https://curl.se/docs/CVE-2025-0167.html","URL":"https://curl.se/docs/CVE-2025-0167.json"},"affected":[{"ranges":[{"type":"SEMVER","events":[{"introduced":"7.76.0"},{"fixed":"8.12.0"}]},{"type":"GIT","repo":"https://github.com/curl/curl.git","events":[{"introduced":"46620b97431e19c53ce82e55055c85830f088cf4"},{"fixed":"0e120c5b925e8ca75d5319e319e5ce4b8080d8eb"}]}],"versions":["8.11.1","8.11.0","8.10.1","8.10.0","8.9.1","8.9.0","8.8.0","8.7.1","8.7.0","8.6.0","8.5.0","8.4.0","8.3.0","8.2.1","8.2.0","8.1.2","8.1.1","8.1.0","8.0.1","8.0.0","7.88.1","7.88.0","7.87.0","7.86.0","7.85.0","7.84.0","7.83.1","7.83.0","7.82.0","7.81.0","7.80.0","7.79.1","7.79.0","7.78.0","7.77.0","7.76.1","7.76.0","curl-8_11_1","curl-8_11_0","curl-8_10_1","curl-8_10_0","curl-8_9_1","curl-8_9_0","curl-8_8_0","curl-8_7_1","curl-8_7_0","curl-8_6_0","curl-8_5_0","tiny-curl-8_4_0","curl-8_4_0","curl-8_3_0","curl-8_2_1","curl-8_2_0","curl-8_1_2","curl-8_1_1","curl-8_1_0","curl-8_0_1","curl-8_0_0","curl-7_88_1","curl-7_88_0","curl-7_87_0","curl-7_86_0","curl-7_85_0","curl-7_84_0","curl-7_83_1","curl-7_83_0","curl-7_82_0","curl-7_81_0","curl-7_80_0","curl-7_79_1","curl-7_79_0","curl-7_78_0","curl-7_77_0","curl-7_76_1","curl-7_76_0"],"database_specific":{"source":"https://curl.se/docs/CURL-CVE-2025-0167.json","vanir_signatures_modified":"2026-05-29T05:40:22Z","vanir_signatures":[{"source":"https://github.com/curl/curl.git/commit/0e120c5b925e8ca75d5319e319e5ce4b8080d8eb","target":{"file":"lib/netrc.c"},"deprecated":false,"digest":{"line_hashes":["20458848727035232539463676160844715969","90706272737080507433274527716916664546","16917327258350909374225622337481945083","95294599251604326993271975417061449667","69955327080921055285093850767477732234","68948961411026234800199585682669406206","191585321479983056735666444989778000369"],"threshold":0.9},"id":"CURL-CVE-2025-0167-15d6fd1f","signature_type":"Line","signature_version":"v1"},{"digest":{"function_hash":"7801934723948004267281319048702801809","length":3446},"id":"CURL-CVE-2025-0167-9ba894d6","signature_type":"Function","signature_version":"v1","source":"https://github.com/curl/curl.git/commit/0e120c5b925e8ca75d5319e319e5ce4b8080d8eb","target":{"file":"lib/netrc.c","function":"parsenetrc"},"deprecated":false}]}}],"schema_version":"1.7.5","credits":[{"name":"Yihang Zhou","type":"FINDER"},{"name":"Daniel Stenberg","type":"REMEDIATION_DEVELOPER"}]}