AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-28322

LOW · CVSS 3.7 EPSS 2.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-05-26 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-28322
Severity
LOW
CVSS
3.7
EPSS
2.21%

Original NVD Description

An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the second transfer. The problem exists in the logic for a reused handle when it is (expected to be) changed from a PUT to a POST.

Related CVEs

Other vulnerabilities affecting the same vendor(s)