logo

Vulnerability in curl and libcurl Could Lead to Heap Buffer Overflow

ID: 05b8abcc-81f8-50b8-894f-7f697c9048e8

STIX ID: report--05b8abcc-81f8-50b8-894f-7f697c9048e8

Feed Name: Aqua Security Blog

Threat Score
75/100

Date Published: 2023-10-11

Date Updated: 2026-04-26

...
...

Aqua Security advisory on CVE-2023-38545: a high-severity heap buffer overflow in curl/libcurl occurring during SOCKS5 proxy hostname resolution when a crafted, overly long hostname is handled (for example via an attacker-controlled 30x redirect). The report details the technical root cause, exploitation prerequisites (attacker-controlled HTTPS server, automatic redirect-following, proxy-resolver-mode), potential impacts including denial-of-service and possible remote code execution, and recommends remediation (upgrade to curl 8.4.0, apply patches, avoid proxy-resolver-mode/socks5h) plus detection via Aqua CNAPP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.