Microsoft Security Response Center guidance
CBL-Mariner Releases
Vendor-listed releases
- 8.8.0-6
- 8.11.1-3
Vulnerability intelligence
CVE-2025-0167 and is rated Low severity with a CVSS score of 3.4. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.