Critical severity9.1NVD Advisory· Published Feb 23, 2023· Updated Jun 17, 2026
CVE-2023-23914
CVE-2023-23914
Description
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords5 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%20Micro%205.3pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
< 7.79.1-150400.5.15.1+ 4 more
- (no CPE)range: < 7.79.1-150400.5.15.1
- (no CPE)range: < 7.79.1-150400.5.15.1
- (no CPE)range: < 7.88.1-1.1
- (no CPE)range: < 7.79.1-150400.5.15.1
- (no CPE)range: < 7.79.1-150400.5.15.1
Patches
Vulnerability mechanics
References
3- hackerone.com/reports/1813864nvdExploitIssue Tracking
- security.gentoo.org/glsa/202310-12nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20230309-0006/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.