Vulnerability Database

296,137

Total vulnerabilities in the database

CVE-2025-0167

When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has a default entry that omits both login and password. A rare circumstance.

No technical information available.

No CWE or OWASP classifications available.