CVE-2023-38039 is a heap memory exhaustion vulnerability in curl versions 7.84 through 8.2.1, affecting products like fedoraproject, haxx, and microsoft. A malicious server can exploit this by sending an unlimited number or size of HTTP headers, causing curl to run out of memory. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, leading to high availability impact. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.84.0, < 8.3.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
< 10.0.17763.5122CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk User Behavior Analytics (UBA) - July 2025
Jul 30, 2025Hackerone: CVE-2023-38039 HTTP headers eat all memory
Oct 10, 2023curl: out of heap memory issue due to missing limit on header quantity
Sep 13, 2023HTTP headers eat all memory
Sep 13, 2023