Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-0167

16
FAUCET Score

CVE-2025-0167 is a low-severity vulnerability affecting curl, specifically when used by products like haxx and NetApp. It allows for potential password leakage if curl is configured to use a .netrc file for credentials, follow HTTP redirects, and the .netrc file contains a specific "default" entry. The attack requires user interaction (UI:R) and has high attack complexity (AC:H), with a CVSS score of 3.4. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion, though it has garnered minimal media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.76.0, < 8.12.0CPE matchmatch criteria
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.4LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.66%
Probability of exploitation in next 30 days
EPSS Percentile
47.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0066 is in the 72nd percentile among its peer group of 233 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

hikvisionpatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: cbl2 curl 8.8.0-6 on CBL Mariner 2.0Fixed in: 8.8.0-6
microsoftpatch availablevia msrc
Product: azl3 curl 8.11.1-3 on Azure Linux 3.0Fixed in: 8.11.1-3
microsoftpatch availablevia msrc
Product: 20047-17086
microsoftpatch availablevia msrc
Product: 17464-17084
microsoftpatch availablevia msrc
Product: cbl2 cmake 3.21.4-18 on CBL Mariner 2.0
microsoftpatch availablevia msrc
Product: 19799-17086Fixed in: 8.8.0-6
microsoftpatch availablevia msrc
Product: azl3 cmake 3.30.3-6 on Azure Linux 3.0
microsoftpatch availablevia msrc
Product: 19252-17084Fixed in: 8.11.1-3
moodlepatch availablevia llm_extracted
Fixed in: 10.0.1, 9.4.5, 9.3.7, 9.2.9
nodejspatch availablevia llm_extracted
Fixed in: 9.4.3, 9.3.5, 9.2.7, 9.1.10
ubuntupatch availablevia ubuntu_usn
Product: curl (jammy)Fixed in: 7.81.0-1ubuntu1.23
ubuntupatch availablevia ubuntu_usn
Product: curl (questing)Fixed in: 8.14.1-2ubuntu1.2
ubuntupatch availablevia ubuntu_usn
Product: curl (noble)Fixed in: 8.5.0-2ubuntu10.8

Vendor Advisories (5)

ubuntuUSN-8084-1

curl vulnerabilities

Mar 11, 2026
moodlellm-moodle-56ca74b6738b856bHIGH

Third-Party Package Updates in Splunk Enterprise - November 2025

Nov 12, 2025
nodejsllm-nodejs-b263506120f02d37CRITICAL

Third-Party Package Updates in Splunk Enterprise - July 2025

Jul 7, 2025
microsoft2025-Feb/CVE-2025-0167Low

netrc and default credential leak

Feb 11, 2025
hikvisionllm-hikvision-6a17b9eb7818a1d0LOW

netrc and default credential leak

Feb 5, 2025

References

curl.se / docs/CVE-2025-0167.html
Vendor Advisory
curl.se / docs/CVE-2025-0167.json
Vendor Advisory
hackerone.com / reports/2917232
ExploitIssue TrackingThird Party Advisory
security.netapp.com / advisory/ntap-20250306-0008
Third Party Advisory