Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-0725


When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.


Published

2025-02-05T10:15:22.980

Last Modified

2025-06-27T19:24:08.327

Status

Analyzed

Source

2499f714-1537-4658-8207-48ae4bb9eae9

Severity

CVSSv3.1: 7.3 (HIGH)

Weaknesses
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netapp hci_baseboard_management_controller - Yes
Operating System netapp hci_h610s_firmware - Yes
Hardware netapp hci_h610s - No
Operating System netapp hci_h610c_firmware - Yes
Hardware netapp hci_h610c - No
Operating System netapp hci_h615c_firmware - Yes
Hardware netapp hci_h615c - No
Application netapp solidfire_\&_hci_management_node - Yes
Application netapp solidfire_\&_hci_storage_node - Yes
Application haxx curl < 8.12.0 Yes
Application haxx libcurl < 8.12.0 Yes
Application zlib zlib ≤ 1.2.0.3 No

References