← Back to CVE List
CVE-2025-0725
When libcurl is asked to perform automatic gzip decompression of
content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option,
**using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would
make libcurl perform a buffer overflow.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt