ThreatCluster

Multiple Vulnerabilities in curl Affect HSTS Functionality

First seen 18 Feb 2026, 14:22 UTC Api.Msrc.Microsoft 56

Article Content

Browse articles
ThreatCluster

Two vulnerabilities affecting curl versions below 7.88.0 have been identified. CVE-2022-43551, published on 2022-12-23, allows HSTS checks to be bypassed using IDN characters, leading to potential cleartext transmissions. CVE-2023-23914, published on 2023-02-23, could cause HSTS functionality to fail when multiple URLs are requested serially, exposing sensitive information.

Timeline

2022-12-23
CVE-2022-43551 published
2023-02-23
CVE-2023-23914 published
2026-02-18
Information published about both vulnerabilities