curl's HSTS check could be bypassed to trick it to keep using HTTP by using a trailing dot in the hostname of the given URL while the HSTS cache was buillt without it or the other way around.
curl's HSTS check could be bypassed to trick it to keep using HTTP by using a trailing dot in the hostname of the given URL while the HSTS cache was buillt without it or the other way around.
https://seclists.org/oss-sec/2022/q2/97 https://curl.se/docs/CVE-2022-30115.html https://github.com/curl/curl/commit/fae6fea209a2d4d https://github.com/curl/curl/commit/b27ad8e1d3e68e
Affected versions: curl 7.82.0 to and including 7.83.0 Not affected versions: curl < 7.82.0 and curl >= 7.83.1