CVE-2025-0167: Haxx Curl

Low severity, CVSS 3.4. EPSS: 0.7% chance of exploitation in the next 30 days.

When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.

Affected products

  • Haxx Curl: from 7.76.0, before 8.12.0 (fixed in 8.12.0)
  • Netapp Bootstrap OS: affected versions not specified
  • Netapp Element Software: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h610c Firmware: affected versions not specified
  • Netapp h610s Firmware: affected versions not specified
  • Netapp h615c Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Ontap: version 9 only
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Netapp Ontap Tools: version 9 only
  • Netapp Solidfire & Hci Management Node: affected versions not specified
  • Netapp Solidfire & Hci Storage Node: affected versions not specified

Published 2025-02-05. Last modified 2026-06-17.