When libcurl is asked to perform automatic gzip decompression of
content-encoded HTTP responses with the CURLOPT_ACCEPT_ENCODING
option,
using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would
make libcurl perform a buffer overflow.
{ "issue": "https://hackerone.com/reports/2956023", "affects": "both", "package": "curl", "CWE": { "id": "CWE-680", "desc": "Integer Overflow to Buffer Overflow" }, "severity": "Low", "www": "https://curl.se/docs/CVE-2025-0725.html", "award": { "currency": "USD", "amount": "505" }, "last_affected": "8.11.1", "URL": "https://curl.se/docs/CVE-2025-0725.json" }