A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
Conclusion & alert: CVE-2023-23914 is rated High Exploit Risk (61.8/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.11%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-01-14 | 0.18% | 0.11% | -0.07% |
| 2 | 2026-01-04 | 0.10% | 0.18% | +0.08% |
| 3 | 2026-01-01 | — | 0.10% | — |
Full EPSS history (19 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2023-23914: 1 source package rows (curl); 52 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 7, open 45. | https://security.alpinelinux.org/vuln/CVE-2023-23914 |
debian
|
not yet assigned | CVE-2023-23914 not yet assigned priority: Debian including 1 source packages (curl), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 1. | https://security-tracker.debian.org/tracker/CVE-2023-23914 |
gentoo
|
high | CVE-2023-23914: 1 GLSA(s) (202310-12), 1 atom(s) (net-misc/curl); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2023-23914 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-23914 |
suse
|
high | CVE-2023-23914 severity important: SUSE including 351 source package names (0.58.0.1.160:libcurl4-7.79.1-150400.5.15.1, 0.58.0.17.153:curl-7.79.1-150400.5.15.1, …), 811 product×package rows across 252 product lines (Container bci/bci-init, Container bci/dotnet-aspnet, … (252 product lines)): Fixed 572, Known Affected 146, Known Not Affected 93. | https://www.suse.com/security/cve/CVE-2023-23914/ |
ubuntu
|
low | CVE-2023-23914 low priority: Ubuntu including 1 source packages (curl), 8 status rows across 8 suites (bionic, focal, jammy, kinetic, lunar, trusty, upstream, xenial): not-affected 4, released 4. | https://ubuntu.com/security/CVE-2023-23914 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| haxx | curl | >= 7.77.0, < 7.88.0 | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
| netapp | clustered_data_ontap | 9.0 | cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:* |
| netapp | h300s_firmware | — | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
| netapp | h500s_firmware | — | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
| netapp | h700s_firmware | — | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
| netapp | h410s_firmware | — | cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* |
| splunk | universal_forwarder | >= 8.2.0, < 8.2.12 | cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* |
| splunk | universal_forwarder | >= 9.0.0, < 9.0.6 | cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:* |
| splunk | universal_forwarder | 9.1.0 | cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://hackerone.com/reports/1813864 | Exploit Issue Tracking |
| https://security.gentoo.org/glsa/202310-12 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20230309-0006/ | Third Party Advisory |