CVE-2024-9681
published 2024-11-06CVE-2024-9681: When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise…
PriorityP339medium6.5CVSS 3.1
AVNACHPRNUINSUCNIHAL
EPSS
2.03%
79.0th percentile
When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
otherwise intended.
This affects curl using applications that enable HSTS and use URLs with the
insecure `HTTP://` scheme and perform transfers with hosts like
`x.example.com` as well as `example.com` where the first host is a subdomain
of the second host.
(The HSTS cache either needs to have been populated manually or there needs to
have been previous HTTPS accesses done as the cache needs to have entries for
the domains involved to trigger this problem.)
When `x.example.com` responds with `Strict-Transport-Security:` headers, this
bug can make the subdomain's expiry timeout *bleed over* and get set for the
parent domain `example.com` in curl's HSTS cache.
The result of a triggered bug is that HTTP accesses to `example.com` get
converted to HTTPS for a different period of time than what was asked for by
the origin server. If `example.com` for example stops supporting HTTPS at its
expiry time, curl might then fail to access `http://example.com` until the
(wrongly set) timeout expires. This bug can also expire the parent's entry
*earlier*, thus making curl inadvertently switch back to insecure HTTP earlier
than otherwise intended.
Affected
73 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_18.4_and_ipados | — | — |
| apple | ipados | — | — |
| apple | macos_sequoia | — | — |
| apple | macos_sonoma | — | — |
| apple | macos_ventura | — | — |
| apple | tvos | — | — |
| apple | visionos | — | — |
| apple | watchos | — | — |
| curl | curl | 7.74.0 – 7.74.0 | — |
| curl | curl | 7.75.0 – 7.75.0 | — |
| curl | curl | 7.76.0 – 7.76.0 | — |
| curl | curl | 7.76.1 – 7.76.1 | — |
| curl | curl | 7.77.0 – 7.77.0 | — |
| curl | curl | 7.78.0 – 7.78.0 | — |
| curl | curl | 7.79.0 – 7.79.0 | — |
| curl | curl | 7.79.1 – 7.79.1 | — |
| curl | curl | 7.80.0 – 7.80.0 | — |
| curl | curl | 7.81.0 – 7.81.0 | — |
| curl | curl | 7.82.0 – 7.82.0 | — |
| curl | curl | 7.83.0 – 7.83.0 | — |
| curl | curl | 7.83.1 – 7.83.1 | — |
| curl | curl | 7.84.0 – 7.84.0 | — |
| curl | curl | 7.85.0 – 7.85.0 | — |
| curl | curl | 7.86.0 – 7.86.0 | — |
| curl | curl | 7.87.0 – 7.87.0 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Third-Party Components in SINEC OS
cisa_ics·2025-08-14
Siemens Third-Party Components in SINEC OS
ICS Advisory
##
Siemens Third-Party Components in SINEC OS
Release DateAugust 14, 2025
Alert CodeICSA-25-226-07
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Third-Party Components in SINEC OS
- Vulnerabilities: Improper Input Validation, Use After Free, Out-of-bounds Read,
Apple
CVE-2024-9681: watchOS 11.4
vendor_apple·2025-04-01·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: watchOS 11.4
Apple Security Update: About the security content of watchOS 11.4
Product: watchOS
Version: 11.4
CVE: CVE-2024-9681
Component: CVE-2024-9681
Apple
CVE-2024-9681: macOS Sonoma 14.7.5
vendor_apple·2025-03-31·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: macOS Sonoma 14.7.5
Apple Security Update: About the security content of macOS Sonoma 14.7.5
Product: macOS Sonoma
Version: 14.7.5
CVE: CVE-2024-9681
Component: CVE-2024-9681
Apple
CVE-2024-9681: iOS 18.4 and iPadOS 18.4
vendor_apple·2025-03-31·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: iOS 18.4 and iPadOS 18.4
Apple Security Update: About the security content of iOS 18.4 and iPadOS 18.4
Product: iOS 18.4 and iPadOS
Version: 18.4
CVE: CVE-2024-9681
Component: CVE-2024-9681
Apple
CVE-2024-9681: tvOS 18.4
vendor_apple·2025-03-31·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: tvOS 18.4
Apple Security Update: About the security content of tvOS 18.4
Product: tvOS
Version: 18.4
CVE: CVE-2024-9681
Component: CVE-2024-9681
Apple
CVE-2024-9681: macOS Ventura 13.7.5
vendor_apple·2025-03-31·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: macOS Ventura 13.7.5
Apple Security Update: About the security content of macOS Ventura 13.7.5
Product: macOS Ventura
Version: 13.7.5
CVE: CVE-2024-9681
Component: CVE-2024-9681
Apple
CVE-2024-9681: macOS Sequoia 15.4
vendor_apple·2025-03-31·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: macOS Sequoia 15.4
Apple Security Update: About the security content of macOS Sequoia 15.4
Product: macOS Sequoia
Version: 15.4
CVE: CVE-2024-9681
Component: CVE-2024-9681
Apple
CVE-2024-9681: visionOS 2.4
vendor_apple·2025-03-31·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: visionOS 2.4
Apple Security Update: About the security content of visionOS 2.4
Product: visionOS
Version: 2.4
CVE: CVE-2024-9681
Component: CVE-2024-9681
Apple
CVE-2024-9681: iPadOS 17.7.6
vendor_apple·2025-03-31·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: iPadOS 17.7.6
Apple Security Update: About the security content of iPadOS 17.7.6
Product: iPadOS
Version: 17.7.6
CVE: CVE-2024-9681
Component: CVE-2024-9681
Ubuntu
curl vulnerability
vendor_ubuntu·2024-11-18
CVE-2024-9681 curl vulnerability
Title: curl vulnerability
Summary: curl could be made to expose sensitive information over the network.
It was discovered that curl could overwrite the HSTS expiry of the parent
domain with the subdomain's HSTS entry. This could lead to curl switching
back to insecure HTTP earlier than otherwise intended, resulting in
information exposure.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
HSTS subdomain overwrites parent cache entry
vendor_msrc·2024-11-12·CVSS 6.5
CVE-2024-9681 [MEDIUM] CWE-697 HSTS subdomain overwrites parent cache entry
HSTS subdomain overwrites parent cache entry
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
curl: curl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.co
Red Hat
curl: HSTS subdomain overwrites parent cache entry
vendor_redhat·2024-11-06·CVSS 6.5
CVE-2024-9681 [MEDIUM] CWE-1025 curl: HSTS subdomain overwrites parent cache entry
curl: HSTS subdomain overwrites parent cache entry
When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
otherwise intended.
This affects curl using applications that enable HSTS and use URLs with the
insecure `HTTP://` scheme and perform transfers with hosts like
`x.example.com` as well as `example.com` where the first host is a subdomain
of the second host.
(The HSTS cache either needs to have been populated manually or there needs to
have been previous HTTPS accesses done as the cache needs to have entries for
the domains involved to trigger this problem.)
When `x.example.com` responds with `Strict-Transport-Security:` headers, this
bug can make the subdomain's expiry timeout *bleed over* and ge
Debian
CVE-2024-9681: curl - When curl is asked to use HSTS, the expiry time for a subdomain might overwrite ...
vendor_debian·2024·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: curl - When curl is asked to use HSTS, the expiry time for a subdomain might overwrite ...
When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like `x.example.com` as well as `example.com` where the first host is a subdomain of the second host. (The HSTS cache either needs to have been populated manually or there needs to have been previous HTTPS accesses done as the cache needs to have entries for the domains involved to trigger this problem.) When `x.example.com` responds with `Strict-Transport-Security:` headers, this bug can make the subdomain's expiry timeout *bleed over* and get set for the parent domain `example.com` in curl's
OSV
CVE-2024-9681: When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
othe
osv·2024-11-06·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
othe
When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
otherwise intended.
This affects curl using applications that enable HSTS and use URLs with the
insecure `HTTP://` scheme and perform transfers with hosts like
`x.example.com` as well as `example.com` where the first host is a subdomain
of the second host.
(The HSTS cache either needs to have been populated manually or there needs to
have been previous HTTPS accesses done as the cache needs to have entries for
the domains involved to trigger this problem.)
When `x.example.com` responds with `Strict-Transport-Security:` headers, this
bug can make the subdomain's expiry timeout *bleed over* and get set for the
parent domain `example.com` in curl
GHSA
GHSA-g337-g667-mjvw: When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
othe
ghsa_unreviewed·2024-11-06
CVE-2024-9681 [MEDIUM] CWE-697 GHSA-g337-g667-mjvw: When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
othe
When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
otherwise intended.
This affects curl using applications that enable HSTS and use URLs with the
insecure `HTTP://` scheme and perform transfers with hosts like
`x.example.com` as well as `example.com` where the first host is a subdomain
of the second host.
(The HSTS cache either needs to have been populated manually or there needs to
have been previous HTTPS accesses done as the cache needs to have entries for
the domains involved to trigger this problem.)
When `x.example.com` responds with `Strict-Transport-Security:` headers, this
bug can make the subdomain's expiry timeout *bleed over* and get set for the
parent domain `example.com` in curl
OSV
CVE-2024-9681: When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than othe
osv·2024-11-06·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than othe
When curl is asked to use HSTS, the expiry time for a subdomain might overwrite a parent domain's cache entry, making it end sooner or later than otherwise intended. This affects curl using applications that enable HSTS and use URLs with the insecure `HTTP://` scheme and perform transfers with hosts like `x.example.com` as well as `example.com` where the first host is a subdomain of the second host. (The HSTS cache either needs to have been populated manually or there needs to have been previous HTTPS accesses done as the cache needs to have entries for the domains involved to trigger this problem.) When `x.example.com` responds with `Strict-Transport-Security:` headers, this bug can make the subdomain's expiry timeout *bleed over* and get set for the parent domain `example.com` in curl's
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2024-9681: HSTS subdomain overwrites parent cache entry
hackerone·2024-11-06·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681: HSTS subdomain overwrites parent cache entry
CVE-2024-9681: HSTS subdomain overwrites parent cache entry
## Summary:
Suppose my HSTS cache file has the following content:
```
.domain.com "20241107 01:02:03"
.sub.domain.com "unlimited"
```
Now, I connect to https://sub.domain.com/. Suppose this domain now sets a HSTS policy: `Strict-Transport-Security: max-age=15768000 ; includeSubDomains`. Surprisingly my HSTS cache file now becomes:
```
.domain.com "unlimited"
.sub.domain.com "20250408 00:26:19"
```
While the HSTS policy for "sub.domain.com" is correctly updated, the HSTS expiration time for "domain.com" is mistakenly set to be the previous expiration time for "sub.domain.com".
If I have multiple levels of subdomains in my HSTS cache, the situation is more confusing. Suppose my HSTS cache is:
```
.com "20241108 01:02:03"
.badssl.c
Bugzilla
CVE-2024-9681 curl: HSTS subdomain overwrites parent cache entry
bugzilla·2024-10-31·CVSS 6.5
CVE-2024-9681 [MEDIUM] CVE-2024-9681 curl: HSTS subdomain overwrites parent cache entry
CVE-2024-9681 curl: HSTS subdomain overwrites parent cache entry
When curl is asked to use HSTS, the expiry time for a subdomain might
overwrite a parent domain's cache entry, making it end sooner or later than
otherwise intended.
This affects curl using applications that enable HSTS and use URLs with the
insecure `HTTP://` scheme and perform transfers with hosts like
`x.example.com` as well as `example.com` where the first host is a subdomain
of the second host.
(The HSTS cache either needs to have been populated manually or there needs to
have been previous HTTPS accesses done as the cache needs to have entries for
the domains involved to trigger this problem.)
When `x.example.com` responds with `Strict-Transport-Security:` headers, this
bug can make the subdomain's expiry timeout *b
https://curl.se/docs/CVE-2024-9681.htmlhttps://curl.se/docs/CVE-2024-9681.jsonhttps://hackerone.com/reports/2764830http://seclists.org/fulldisclosure/2025/Apr/10http://seclists.org/fulldisclosure/2025/Apr/11http://seclists.org/fulldisclosure/2025/Apr/12http://seclists.org/fulldisclosure/2025/Apr/13http://seclists.org/fulldisclosure/2025/Apr/4http://seclists.org/fulldisclosure/2025/Apr/5http://seclists.org/fulldisclosure/2025/Apr/8http://seclists.org/fulldisclosure/2025/Apr/9http://www.openwall.com/lists/oss-security/2024/11/06/2https://security.netapp.com/advisory/ntap-20241213-0006/
2024-11-06
Published