CVE-2025-0167: Haxx Curl
Low severity, CVSS 3.4. EPSS: 0.7% chance of exploitation in the next 30 days.
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
Affected products
- Haxx Curl: from 7.76.0, before 8.12.0 (fixed in 8.12.0)
- Netapp Bootstrap OS: affected versions not specified
- Netapp Element Software: affected versions not specified
- Netapp h300s Firmware: affected versions not specified
- Netapp h410c Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h610c Firmware: affected versions not specified
- Netapp h610s Firmware: affected versions not specified
- Netapp h615c Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
- Netapp Ontap: version 9 only
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
- Netapp Ontap Tools: version 9 only
- Netapp Solidfire & Hci Management Node: affected versions not specified
- Netapp Solidfire & Hci Storage Node: affected versions not specified
Published 2025-02-05. Last modified 2026-06-17.