CVE-2023-28319: Apple macOS

High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.

A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprint before it returns an error message containing the (now freed) hash. This flaw risks inserting sensitive heap-based data into the error message that might be shown to users or otherwise get leaked and revealed.

Affected products

  • Apple macOS: from 11.0, before 11.7.9 (fixed in 11.7.9); from 12.0, before 12.6.8 (fixed in 12.6.8); from 13.0, before 13.5 (fixed in 13.5)
  • Haxx Curl: before 8.1.0 (fixed in 8.1.0)
  • Netapp Clustered Data Ontap: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Ontap Antivirus Connector: affected versions not specified

Published 2023-05-26. Last modified 2026-06-17.