High severity7.5NVD Advisory· Published Sep 15, 2023· Updated Jun 17, 2026
CVE-2023-38039
CVE-2023-38039
Description
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.
However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*range: <10.0.19044.3693
- cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*range: <10.0.19045.3693
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*range: <10.0.22621.2715
- cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*range: <10.0.22631.2715
- cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*Range: <10.0.17763.5122
- cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*Range: <10.0.20348.2113
- osv-coords10 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 8.0.1-150400.5.29.1+ 9 more
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.3.0-1.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-11.71.1
- (no CPE)range: < 8.0.1-11.71.1
- (no CPE)range: < 8.0.1-11.71.1
Patches
Vulnerability mechanics
References
15- hackerone.com/reports/2072338nvdExploitIssue TrackingPatchThird Party Advisory
- seclists.org/fulldisclosure/2023/Oct/17nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jan/34nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jan/37nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jan/38nvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202310-12nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20231013-0005/nvdThird Party Advisory
- support.apple.com/kb/HT214036nvdThird Party Advisory
- support.apple.com/kb/HT214057nvdThird Party Advisory
- support.apple.com/kb/HT214058nvdThird Party Advisory
- support.apple.com/kb/HT214063nvdThird Party Advisory
- www.insyde.com/security-pledge/SA-2023064nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/5DCZMYODALBLVOXVJEN2LF2MLANEYL4F/nvdMailing List
- lists.fedoraproject.org/archives/list/[email protected]/message/M6KGKB2JNZVT276JYSKI6FV2VFJUGDOJ/nvdMailing List
- lists.fedoraproject.org/archives/list/[email protected]/message/TEAWTYHC3RT6ZRS5OZRHLAIENVN6CCIS/nvdMailing List
News mentions
0No linked articles in our index yet.