CVE-2023-46219: Fedoraproject Fedora
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.
Affected products
- Fedoraproject Fedora: version 38 only
- Haxx Curl: from 7.84.0, before 8.5.0 (fixed in 8.5.0)
Published 2023-12-12. Last modified 2026-06-17.