Microsoft Security Response Center guidance
CBL-Mariner Releases
Vendor-listed releases
- 8.0.40-4
- 8.11.1-3
- 8.0.40-6
- 8.0.42-1
Vulnerability intelligence
CVE-2025-0725 and is rated High severity with a CVSS score of 7.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.