CVE-2023-38545: curl SOCKS5 Heap Overflow
A heap buffer overflow in curl and libcurl's SOCKS5 proxy handshake. When curl is told to let the SOCKS5 proxy resolve a hostname longer than 255 bytes, a logic bug can make curl instead copy the full oversized hostname into a fixed-size local buffer, corrupting the heap.
View the authoritative record on NVD ↗Affected software
- curl and libcurl 7.69.0 through 8.3.0
How it's exploited
Cause curl to perform a slow SOCKS5 handshake against a malicious or attacker-influenced proxy using a hostname just over the 255-byte remote-resolution limit; a timing-dependent bug makes curl copy the oversized hostname into a fixed-size buffer instead of resolving it locally, corrupting adjacent heap memory.
Severity
CVE-2023-38545 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2023-38545 is categorized under CWE-787, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade curl and libcurl to 8.4.0 or later; there is no configuration-only workaround since the flaw is in SOCKS5 handshake handling itself.
Frequently asked questions
What is CVE-2023-38545?
A heap buffer overflow in curl and libcurl's SOCKS5 proxy handshake. When curl is told to let the SOCKS5 proxy resolve a hostname longer than 255 bytes, a logic bug can make curl instead copy the full oversized hostname into a fixed-size local buffer, corrupting the heap.
How severe is CVE-2023-38545?
CVE-2023-38545 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2023-38545?
CVE-2023-38545 affects curl and libcurl 7.69.0 through 8.3.0.
How do you fix CVE-2023-38545?
Upgrade curl and libcurl to 8.4.0 or later; there is no configuration-only workaround since the flaw is in SOCKS5 handshake handling itself.
Where is the authoritative record for CVE-2023-38545?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2023-38545 at https://nvd.nist.gov/vuln/detail/CVE-2023-38545, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest