VYPR
Low severity3.4NVD Advisory· Published Feb 5, 2025· Updated Jun 17, 2026

CVE-2025-0167

CVE-2025-0167

Description

When asked to use a .netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.

This flaw only manifests itself if the netrc file has a default entry that omits both login and password. A rare circumstance.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

39

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.