CVE Database
/

CVE-2025-0725

Back to search

CVE-2025-0725

Published: Feb 5, 2025

Modified: Jun 12, 2025

PUBLISHED

Description

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

VendorProductVersions

curl

curl

affected
8.11.1 - <= 8.11.1
affected
8.11.0 - <= 8.11.0
affected
8.10.1 - <= 8.10.1
affected
8.10.0 - <= 8.10.0
affected
8.9.1 - <= 8.9.1

+157 more versions

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now