Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-23916

23
FAUCET Score

CVE-2023-23916 is an allocation of resources without limits vulnerability in curl versions prior to 7.88.0, affecting products like Debian, Fedora, NetApp, and Splunk. A malicious server can trigger a "malloc bomb" by chaining multiple HTTP compression algorithms, leading to excessive memory allocation and potential denial of service. With a CVSS score of 6.5 (Medium), this vulnerability requires user interaction (UI:R) but has a high impact on availability (A:H). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.57.0, < 7.88.0CPE matchmatch criteria
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.70%
Probability of exploitation in next 30 days
EPSS Percentile
74.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0170 is in the 87th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (50)

hikvisionpatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: azl3 tensorflow 2.16.1-1 on Azure Linux 3.0Fixed in: 2.16.1-1
microsoftpatch availablevia msrc
Product: cm1 rust 1.59.0-1 on CBL Mariner 1.0Fixed in: 1.59.0-1
microsoftpatch availablevia msrc
Product: cm1 mysql 8.0.32-1 on CBL Mariner 1.0Fixed in: 8.0.32-1
microsoftpatch availablevia msrc
Product: cm1 curl 7.88.1-1 on CBL Mariner 1.0Fixed in: 7.88.1-1
microsoftpatch availablevia msrc
Product: cbl2 curl 7.88.1-1 on CBL Mariner 2.0Fixed in: 7.88.1-1
microsoftpatch availablevia msrc
Product: cm1 cmake 3.21.4-3 on CBL Mariner 1.0Fixed in: 3.21.4-3
microsoftpatch availablevia msrc
Product: cbl2 rust 1.72.0-2 on CBL Mariner 2.0Fixed in: 1.72.0-2
microsoftpatch availablevia msrc
Product: cbl2 mysql 8.0.33-1 on CBL Mariner 2.0Fixed in: 8.0.33-1
microsoftpatch availablevia msrc
Product: cbl2 cmake 3.21.4-13 on CBL Mariner 2.0Fixed in: 3.21.4-13
microsoftpatch availablevia msrc
Product: azl3 cmake 3.28.2-1 on Azure Linux 3.0Fixed in: 3.28.2-1
microsoftpatch availablevia msrc
Product: azl3 cmake 3.21.4-10 on Azure Linux 3.0Fixed in: 3.28.2-1
microsoftpatch availablevia msrc
Product: azl3 tensorflow 2.11.1-1 on Azure Linux 3.0Fixed in: 2.16.1-1
microsoftpatch availablevia msrc
Product: 17878-17084Fixed in: 2.16.1-1
microsoftpatch availablevia msrc
Product: 17941-16820Fixed in: 1.59.0-1
microsoftpatch availablevia msrc
Product: 17950-16820Fixed in: 8.0.32-1
microsoftpatch availablevia msrc
Product: 17951-16820Fixed in: 7.88.1-1
microsoftpatch availablevia msrc
Product: 17955-16823Fixed in: 7.88.1-1
microsoftpatch availablevia msrc
Product: 17952-16820Fixed in: 3.21.4-3
microsoftpatch availablevia msrc
Product: 17953-16823Fixed in: 1.72.0-2
microsoftpatch availablevia msrc
Product: 17954-16823Fixed in: 8.0.33-1
microsoftpatch availablevia msrc
Product: 17956-16823Fixed in: 3.21.4-13
microsoftpatch availablevia msrc
Product: 17957-17084Fixed in: 3.28.2-1
microsoftpatch availablevia msrc
Product: 17879-17084Fixed in: 3.28.2-1
microsoftpatch availablevia msrc
Product: 18295-17084Fixed in: 2.16.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 1.72.0-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 3.21.4-13
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 7.88.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 8.0.33-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 1.72.0-2
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 7.88.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 7.88.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 3.28.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.16.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 3.28.2-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.16.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 3.21.4-13
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 7.88.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 8.0.33-1
redhatpatch availablevia redhat_api
Product: JBCS httpd 2.4.51.sp2Fixed in: jbcs-httpd24-curl
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-curl-0:8.0.1-1.el7jbcs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: curl-0:7.61.1-25.el8_7.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: curl-0:7.61.1-18.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: curl-0:7.61.1-18.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: curl-0:7.61.1-18.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: curl-0:7.61.1-22.el8_6.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: curl-0:7.76.1-19.el9_1.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: curl-0:7.76.1-14.el9_0.6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services for RHEL 8Fixed in: jbcs-httpd24-curl-0:8.0.1-1.el8jbcs
View patch
zimbrapatch availablevia llm_extracted
Fixed in: 8.2.12, 9.0.6, 9.1.1

Vendor Advisories (5)

microsoft2024-Nov/CVE-2023-23916

CVE-2023-23916

Nov 12, 2024
zimbrallm-zimbra-9542faa91a6d6884HIGH

August Third Party Package Updates in Splunk Universal Forwarder

Aug 30, 2023
redhatCVE-2023-23916Moderate

curl: HTTP multi-header compression denial of service

Feb 15, 2023
hikvisionllm-hikvision-d96921eef4e459f9MEDIUM

HTTP multi-header compression denial of service

Feb 15, 2023
microsoft2023-Feb/CVE-2023-23916Moderate

An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a "malloc bomb" making curl end up spending enormous amounts of allocated heap memory or trying to and returning out of memory errors.

Feb 14, 2023

References

hackerone.com / reports/1826048
ExploitIssue Tracking
lists.debian.org / debian-lts-announce/2023/02/msg00035.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/BQKE6TXYDHOTFHLTBZ5X73GTKI7II5KO
Mailing ListThird Party Advisory
security.gentoo.org / glsa/202310-12
Third Party Advisory
security.netapp.com / advisory/ntap-20230309-0006
Third Party Advisory
debian.org / security/2023/dsa-5365
Third Party Advisory