logo

CVE-2023-38545 high severity vulnerability in cURL: everything you need to know

ID: e2028141-7414-57e0-9fd2-86c5caff5b06

STIX ID: report--e2028141-7414-57e0-9fd2-86c5caff5b06

Feed Name: Wiz Blog

Threat Score
55/100

Date Published: 2023-10-11

Date Updated: 2026-05-01

...
...

Wiz Research reports that CVE-2023-38545 is a heap-based buffer overflow in libcurl’s SOCKS5 proxy handshake affecting libcurl 7.69.0 through 8.3.0; the flaw can occur when curl forwards an overly long hostname to a SOCKS5 proxy and a slow handshake leads to copying the full hostname into a fixed-size buffer. The advisory recommends upgrading to cURL 8.4.0 (or awaiting vendor updates on Windows), notes mitigations and detection guidance, and assesses current exploitation likelihood as relatively low with no known RCE exploits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.