Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-38039

59
FAUCET Score

CVE-2023-38039 is a heap memory exhaustion vulnerability in curl versions 7.84 through 8.2.1, affecting products like fedoraproject, haxx, and microsoft. A malicious server can exploit this by sending an unlimited number or size of HTTP headers, causing curl to run out of memory. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to high availability impact. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.84.0, < 8.3.0CPE matchmatch criteria
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
< 10.0.17763.5122CPE matchmatch criteria
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
62.25%
Probability of exploitation in next 30 days
EPSS Percentile
99.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.6225 is in the 98th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (26)

hikvisionpatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: Windows 11 Version 23H2 for x64-based SystemsFixed in: 10.0.22631.2715
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for 32-bit SystemsFixed in: 10.0.19045.3693
View patch
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 8.3.0-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 8.3.0-1
microsoftpatch availablevia msrc
Product: Windows 11 Version 23H2 for ARM64-based SystemsFixed in: 10.0.22631.2715
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for 32-bit SystemsFixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for x64-based SystemsFixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 1809 for ARM64-based SystemsFixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019Fixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2019 (Server Core installation)Fixed in: 10.0.17763.5122
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022Fixed in: 10.0.20348.2113
View patch
microsoftpatch availablevia msrc
Product: Windows Server 2022 (Server Core installation)Fixed in: 10.0.20348.2113
View patch
microsoftpatch availablevia msrc
Product: Windows 11 version 21H2 for x64-based SystemsFixed in: 10.0.22000.2600
View patch
microsoftpatch availablevia msrc
Product: Windows 11 version 21H2 for ARM64-based SystemsFixed in: 10.0.22000.2600
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for 32-bit SystemsFixed in: 10.0.22000.2600
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for ARM64-based SystemsFixed in: 10.0.19044.3693
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 21H2 for x64-based SystemsFixed in: 10.0.19044.3693
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 22H2 for ARM64-based SystemsFixed in: 10.0.22621.2715
View patch
microsoftpatch availablevia msrc
Product: Windows 11 Version 22H2 for x64-based SystemsFixed in: 10.0.22621.2715
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for x64-based SystemsFixed in: 10.0.19045.3693
View patch
microsoftpatch availablevia msrc
Product: Windows 10 Version 22H2 for ARM64-based SystemsFixed in: 10.0.19045.3693
View patch
nodejspatch availablevia llm_extracted
Fixed in: 5.4.3
redhatpatch availablevia redhat_api
Product: Text-Only JBCSFixed in: jbcs-httpd24-curl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:8.4.0-2.el7jbcs
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-curl-0:8.4.0-2.el8jbcs
View patch

Vendor Advisories (4)

nodejsllm-nodejs-91bc25f14cc604adCRITICAL

Third-Party Package Updates in Splunk User Behavior Analytics (UBA) - July 2025

Jul 30, 2025
microsoft2023-Oct/CVE-2023-38039Low

Hackerone: CVE-2023-38039 HTTP headers eat all memory

Oct 10, 2023
redhatCVE-2023-38039Moderate

curl: out of heap memory issue due to missing limit on header quantity

Sep 13, 2023
hikvisionllm-hikvision-6c2eb186716e7c02MEDIUM

HTTP headers eat all memory

Sep 13, 2023

References

seclists.org / fulldisclosure/2023/Oct/17
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2024/Jan/34
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2024/Jan/37
Mailing ListThird Party Advisory
seclists.org / fulldisclosure/2024/Jan/38
Mailing ListThird Party Advisory
hackerone.com / reports/2072338
ExploitIssue TrackingPatchThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/5DCZMYODALBLVOXVJEN2LF2MLANEYL4F
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/M6KGKB2JNZVT276JYSKI6FV2VFJUGDOJ
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/TEAWTYHC3RT6ZRS5OZRHLAIENVN6CCIS
Mailing List
security.gentoo.org / glsa/202310-12
Third Party Advisory
security.netapp.com / advisory/ntap-20231013-0005
Third Party Advisory
support.apple.com / kb/HT214036
Third Party Advisory
support.apple.com / kb/HT214057
Third Party Advisory
support.apple.com / kb/HT214058
Third Party Advisory
support.apple.com / kb/HT214063
Third Party Advisory
insyde.com / security-pledge/SA-2023064
Third Party Advisory