Here's a link to something other than twitter for those who don't have an account, don't want to login, or don't want to enable javascript
https://github.com/curl/curl/discussions/12026
The CVEs:
CVE-2023-38545: severity HIGH (affects both libcurl and the curl tool)
CVE-2023-38546: severity LOW (affects libcurl only, not the tool)
I really wish people would just stop posting submissions to twitter at this point.