CVE-2023-28322: Apple macOS
Low severity, CVSS 3.7. EPSS: 2.2% chance of exploitation in the next 30 days.
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.
Affected products
- Apple macOS: from 11.0, before 11.7.9 (fixed in 11.7.9); from 12.0, before 12.6.8 (fixed in 12.6.8); from 13.0, before 13.5 (fixed in 13.5)
- Fedoraproject Fedora: version 37 only; version 38 only
- Haxx Curl: before 8.1.0 (fixed in 8.1.0)
- Netapp Clustered Data Ontap: affected versions not specified
- Netapp h300s Firmware: affected versions not specified
- Netapp h410s Firmware: affected versions not specified
- Netapp h500s Firmware: affected versions not specified
- Netapp h700s Firmware: affected versions not specified
- Netapp Ontap Antivirus Connector: affected versions not specified
Published 2023-05-26. Last modified 2026-06-17.