CVE-2025-0725
PoC —CVSS 3.1
7.3 high
EPSS
1%p68
Published
()
Modified
Description
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
In the news0 stories
No ingested article mentions this CVE yet.