When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances.
This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
CVSS Details
- CVSS 3.1 Base Score: 3.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-curl | Aug 8, 2025 | Feb 5, 2025 | |
| Debian | debian-upgrade-curl | Mar 17, 2025 | Feb 5, 2025 | |
| Dell Powerstore Dsa2025342 | dell-powerstoreos-upgrade-latest | Oct 23, 2025 | Sep 2, 2025 | |
| Dell Powerstore Dsa2026039 | dell-powerstoreos-upgrade-latest | Jan 13, 2026 | Jan 6, 2026 | |
| Huawei Euleros 2_0_sp11 | huawei-euleros-2_0_sp11-upgrade-curlhuawei-euleros-2_0_sp11-upgrade-libcurl | Apr 11, 2025 | Feb 5, 2025 | |
| Huawei Euleros 2_0_sp12 | huawei-euleros-2_0_sp12-upgrade-curlhuawei-euleros-2_0_sp12-upgrade-libcurl | May 7, 2025 | Feb 5, 2025 | |
| Huawei Euleros 2_0_sp13 | huawei-euleros-2_0_sp13-upgrade-curlhuawei-euleros-2_0_sp13-upgrade-libcurl | Apr 1, 2025 | Feb 5, 2025 | |
| Ibm Aix | ibm-aix-curl_advisory7 | Nov 6, 2025 | Jun 4, 2025 | |
| Suse | — | suse-upgrade-curlsuse-upgrade-libcurl-develsuse-upgrade-libcurl-devel-32bitsuse-upgrade-libcurl4suse-upgrade-libcurl4-32bit | Feb 10, 2025 | Feb 5, 2025 |
| Ubuntu | ubuntu-upgrade-curlubuntu-upgrade-libcurl3-gnutlsubuntu-upgrade-libcurl3-nssubuntu-upgrade-libcurl3t64-gnutlsubuntu-upgrade-libcurl4ubuntu-upgrade-libcurl4t64 | Jun 26, 2025 | Feb 5, 2025 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jul 2, 2025 | Feb 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub