Unrated severityNVD Advisory· Published Sep 15, 2023· Updated Dec 2, 2025
CVE-2023-38039
CVE-2023-38039
Description
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API.
However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- osv-coords10 versionspkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 8.0.1-150400.5.29.1+ 9 more
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.3.0-1.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-150400.5.29.1
- (no CPE)range: < 8.0.1-11.71.1
- (no CPE)range: < 8.0.1-11.71.1
- (no CPE)range: < 8.0.1-11.71.1
Patches
Vulnerability mechanics
References
15- seclists.org/fulldisclosure/2023/Oct/17mitre
- seclists.org/fulldisclosure/2024/Jan/34mitre
- seclists.org/fulldisclosure/2024/Jan/37mitre
- seclists.org/fulldisclosure/2024/Jan/38mitre
- hackerone.com/reports/2072338mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5DCZMYODALBLVOXVJEN2LF2MLANEYL4F/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M6KGKB2JNZVT276JYSKI6FV2VFJUGDOJ/mitre
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEAWTYHC3RT6ZRS5OZRHLAIENVN6CCIS/mitre
- security.gentoo.org/glsa/202310-12mitre
- security.netapp.com/advisory/ntap-20231013-0005/mitre
- support.apple.com/kb/HT214036mitre
- support.apple.com/kb/HT214057mitre
- support.apple.com/kb/HT214058mitre
- support.apple.com/kb/HT214063mitre
- www.insyde.com/security-pledge/SA-2023064mitre
News mentions
0No linked articles in our index yet.