Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

curl and libcurl 8.4.0, released October 11, 2023, fixed two newly disclosed security flaws: a high-severity heap buffer overflow in a SOCKS5 proxy handshake and a low-severity cookie-injection bug in a specific libcurl API workflow. The first can affect command-line curl users who use SOCKS5 remote hostname resolution; the second affects certain applications that duplicate libcurl easy handles and is not reachable through the curl command-line tool.

What curl 8.4.0 fixed

The curl project released version 8.4.0 on October 11, 2023. In an October 4 announcement, curl maintainer Daniel Stenberg said the release cycle was being shortened to include fixes for one high-severity and one low-severity CVE. The announcement identified CVE-2023-38545 as affecting curl and libcurl, and CVE-2023-38546 as affecting libcurl only. The maintainer announcement and curl version history record the release timing.

Issue Severity Affected interface Affected versions Can affect command-line curl?
CVE-2023-38545, SOCKS5 heap buffer overflow High SOCKS5 proxy handshake when the proxy resolves the hostname libcurl 7.69.0 through 8.3.0 Yes, when used with the affected SOCKS5 remote-resolution mode
CVE-2023-38546, cookie injection with “none” file Low libcurl cookie handling after duplicating an easy handle See the official advisory for the affected range No

Both flaws were fixed in 8.4.0. The version range for CVE-2023-38546 is not specified in the available advisory summary here, so check the official CVE-2023-38546 advisory rather than inferring it from the other flaw’s range.

CVE-2023-38545: SOCKS5 heap buffer overflow

The high-severity flaw affects libcurl 7.69.0 through 8.3.0. The curl advisory lists versions before 7.69.0 and versions 8.4.0 or later as not affected. It classifies the issue as a heap-based buffer overflow (CWE-122). The official advisory describes the vulnerable SOCKS5 handshake.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

When the flaw can be reached

The risk concerns SOCKS5 configurations in which the proxy, rather than the client, resolves the destination hostname. Relevant command-line usage includes --socks5-hostname and socks5h:// proxy URLs supplied through --proxy, --preproxy, or proxy environment variables.

In this mode, SOCKS5 hostnames are limited to 255 bytes. During a slow, non-blocking proxy handshake, an incorrect state value can cause an overlong hostname to be copied into the target buffer instead of the resolved address. This is a conditional flaw, not a claim that every request using curl or every SOCKS5 proxy is vulnerable; the proxy mode and handshake conditions matter.

How to mitigate it

  • Upgrade: use curl/libcurl 8.4.0 or later, or install a vendor package that includes the fix.
  • Patch: apply the project’s fix and rebuild if upgrading is not immediately possible.
  • Reduce exposure temporarily: avoid CURLPROXY_SOCKS5_HOSTNAME in libcurl applications and avoid socks5h:// proxy settings or environment variables. This changes who resolves the hostname and may affect proxy behavior, so verify the alternative configuration suits your network.

CVE-2023-38546: cookie injection in a libcurl handle-duplication workflow

The low-severity flaw requires a particular API sequence in a libcurl application. When cookies are enabled, curl_easy_duphandle() clones the cookie-enabled state without copying the actual cookies. If the original handle did not read a cookie file, the duplicate can retain the literal filename none in its cookie structure. Under the advisory’s conditions, an attacker can cause cookie data to be inserted into the running program. The official advisory describes the trigger and fix.

This issue is not accessible through the curl command-line tool. It is relevant to developers using libcurl who duplicate easy handles while cookies are enabled.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fixes for applications using libcurl

  • Upgrade to curl/libcurl 8.4.0 or later, or apply the project patch and rebuild.
  • If upgrading is not possible, call curl_easy_setopt(cloned_curl, CURLOPT_COOKIELIST, "ALL") immediately after every curl_easy_duphandle() call, as documented by the advisory.

The 8.4.0 fix prevents the filename from being stored in the cookie structure.

How to decide whether you need action

  1. Identify the libcurl version actually in use. A system may contain multiple copies, such as an operating-system package and a separate application bundle. Check the binary or package used by the affected application, not just a version reported by an unrelated curl installation.
  2. For CVE-2023-38545, inspect proxy configuration. Determine whether the client uses SOCKS5 remote hostname resolution through --socks5-hostname, socks5h://, or the equivalent libcurl setting, and whether the libcurl version falls within 7.69.0–8.3.0.
  3. For CVE-2023-38546, inspect application code. Check whether a libcurl program enables cookies and calls curl_easy_duphandle(); this is not a command-line curl exposure.
  4. Install the appropriate fix. Prefer a supported upgrade or a distribution-provided security update. If either is unavailable, use the narrowly relevant mitigation above and plan to move to a fixed package.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the October 11 date means now

This is a historical release notice, not a statement that 8.4.0 is the current curl version. The official version history lists curl 8.22.0 as released September 2, 2026. Later versions can have separate advisories, and operating-system vendors may backport fixes without changing the upstream version number in the way users expect. For example, Ubuntu’s USN-8820-1, published September 24, 2026, documents fixes for several newer curl CVEs in Ubuntu 24.04 LTS and 26.04 LTS. Check curl’s version history and consult your operating system or vendor’s security advisory to verify the package currently installed and its patch status. Ubuntu USN-8820-1 is specific to the named Ubuntu releases.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.