JLSEC-2026-1343

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1343.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1343.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1343
Upstream
  • EUVD-2023-50461
  • GHSA-fj44-3xpp-9cx2
Published
2026-08-17T13:15:13.400Z
Modified
2026-08-17T13:44:05.405693780Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
When saving HSTS data to an excessively long file name, curl could end up removing all contents,...
Details

When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "database_specific": {
                "status": "Modified"
            },
            "id": "CVE-2023-46219",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46219",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-46219",
            "published": "2023-12-12T02:15:06.990Z",
            "modified": "2026-06-17T06:30:23.187Z",
            "imported": "2026-08-16T08:05:13.319Z"
        },
        {
            "id": "GHSA-fj44-3xpp-9cx2",
            "published": "2023-12-12T03:31:45Z",
            "url": "https://api.github.com/advisories/GHSA-fj44-3xpp-9cx2",
            "html_url": "https://github.com/advisories/GHSA-fj44-3xpp-9cx2",
            "modified": "2026-05-12T12:31:34Z",
            "imported": "2026-08-16T08:06:58.606Z"
        },
        {
            "id": "EUVD-2023-50461",
            "published": "2023-12-12T01:38:41Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2023-50461",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-50461",
            "modified": "2026-07-14T12:07:26Z",
            "imported": "2026-08-16T08:05:23.480Z"
        }
    ]
}
References

Affected packages

Julia / LibCURL_jll

Package

Name
LibCURL_jll
Purl
pkg:julia/LibCURL_jll?uuid=deac9b47-8bc7-5906-a0fe-35ac56dc84c0

Affected ranges

Type
SEMVER
Events
Introduced
7.84.0+0
Fixed
8.5.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1343.json"