CVE-2023-27537: Broadcom Brocade Fabric Operating System Firmware

Medium severity, CVSS 5.9. EPSS: 1.9% chance of exploitation in the next 30 days.

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

Affected products

  • Broadcom Brocade Fabric Operating System Firmware: affected versions not specified
  • Haxx Libcurl: version 7.88.0 only; version 7.88.1 only
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Clustered Data Ontap: version 9.0 only
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Splunk Universal Forwarder: from 8.2.0, before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); version 9.1.0 only

Published 2023-03-30. Last modified 2026-06-17.