SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-38039

However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

HIGH 7.5EPSS 57.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 57.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
57.78% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-770
Affected
haxx/curl · fedoraproject/fedora · microsoft/windows 10 1809 · microsoft/windows 10 21h2 · microsoft/windows 10 22h2 · microsoft/windows 11 21h2 · microsoft/windows 11 22h2 · microsoft/windows 11 23h2 · microsoft/windows server 2019 · microsoft/windows server 2022
Source
support@hackerone.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.