CVE-2024-9681 is a medium-severity vulnerability affecting haxx curl, where an HSTS subdomain expiry time can incorrectly overwrite a parent domain's entry in the HSTS cache. This can lead to curl converting HTTP requests to HTTPS for an unintended duration, potentially causing service disruptions or premature reversion to insecure HTTP. With a CVSS score of 6.5, this bug has a high impact on integrity and a low impact on availability, requiring high attack complexity and no user interaction. There is currently no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has garnered some community discussion and media coverage, including a mention in CISA alerts regarding Siemens SINEC OS.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.74.0, < 8.11.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
>= 7.74.0, <= 7.74.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.75.0, <= 7.75.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.76.0, <= 7.76.0CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* | ||
>= 7.76.1, <= 7.76.1CPE match | cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - July 2025
Jul 7, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HSTS subdomain overwrites parent cache entry
Nov 12, 2024curl: HSTS subdomain overwrites parent cache entry
Nov 6, 2024HSTS subdomain overwrites parent cache entry
Nov 5, 2024