When libcurl is asked to perform automatic gzip decompression of
content-encoded HTTP responses with the CURLOPT_ACCEPT_ENCODING
option,
using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would
make libcurl perform a buffer overflow.
{ "CWE": { "id": "CWE-680", "desc": "Integer Overflow to Buffer Overflow" }, "award": { "amount": "505", "currency": "USD" }, "URL": "https://curl.se/docs/CVE-2025-0725.json", "package": "curl", "severity": "Low", "issue": "https://hackerone.com/reports/2956023", "www": "https://curl.se/docs/CVE-2025-0725.html", "last_affected": "8.11.1" }