CVE-2025-0725

HIGH
Published Feb 5, 2025 Modified Jun 27, 2025 CWE-120

Description

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

CVSS v3.1 Score

7.3
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Weakness Type (CWE)

CWE-120 CWE-120

Affected Products

Vendor Product
netapp hci_baseboard_management_controller
netapp hci_h610s_firmware
netapp hci_h610s
netapp hci_h610c_firmware
netapp hci_h610c
netapp hci_h615c_firmware
netapp hci_h615c
netapp solidfire_\&_hci_management_node
netapp solidfire_\&_hci_storage_node
haxx curl
haxx libcurl
zlib zlib

References

Frequently Asked Questions

What is CVE-2025-0725? +
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow. It has a CVSS v3.1 base score of 7.3 (HIGH).
How severe is CVE-2025-0725? +
CVE-2025-0725 has a CVSS v3.1 score of 7.3 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2025-0725? +
CVE-2025-0725 affects products from haxx, netapp, zlib, specifically: curl, hci_baseboard_management_controller, hci_h610c, hci_h610c_firmware, hci_h610s, hci_h610s_firmware, hci_h615c, hci_h615c_firmware, libcurl, solidfire_\&_hci_management_node, solidfire_\&_hci_storage_node, zlib. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2025-0725? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2025-0725 — free, no signup required.

Start Free Scan