Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The October 11, 2023 curl disclosure turned two days of concern into a more specific patching story: CVE-2023-38545 was a High-severity SOCKS5 heap overflow with particular prerequisites, while CVE-2023-38546 was a Low-severity libcurl cookie issue that did not affect the curl command-line tool. Both were fixed in curl 8.4.0, released the same day. The practical question is whether your software used the affected code paths—not whether it used the name “curl.”

What did the curl disclosure actually reveal?

On October 11, 2023, the curl project published advisories for two flaws and released curl 8.4.0 with fixes. The project rated the SOCKS5 flaw High and the cookie flaw Low. Those ratings and the conditions in the advisories are more precise than the “hype fizzles” characterization in Dark Reading’s headline and report.

The headline issue, CVE-2023-38545, could cause a heap-based buffer overflow during a SOCKS5 proxy handshake. The separate CVE-2023-38546 concerned how some libcurl applications handled cookies after duplicating an easy handle. Neither advisory establishes how many products or installations were affected, or that either flaw was being exploited in the wild.

When could CVE-2023-38545 affect a connection?

The overflow depended on a particular combination of proxy behavior, hostname length, buffer size and handshake timing. It was not simply a flaw triggered by every use of curl or every SOCKS5 connection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

The SOCKS5 remote-hostname path

The flaw applied when curl asked the SOCKS5 proxy to resolve the hostname remotely. That mode can be selected with CURLPROXY_SOCKS5_HOSTNAME, a socks5h:// proxy URL, or proxy environment variables using that scheme. SOCKS5 allows at most 255 bytes in its hostname field. For a longer hostname, curl was supposed to resolve it locally and send the resulting address to the proxy.

During a slow SOCKS5 handshake, a faulty state variable could lead curl to copy the oversized hostname into the heap-based download buffer instead. The advisory identifies a heap overflow when that buffer was unset or smaller than 65,541 bytes, alongside the long hostname and slow-handshake conditions.

Why the curl tool’s default did not tell the whole story

The curl command-line tool normally used a 102,400-byte transfer buffer, but rate limiting below 102,400 bytes per second could reduce it. The default libcurl buffer was 16 kB, and an application using libcurl could set a different size. So the command-line tool’s ordinary default was not a blanket safety guarantee for software that embeds the library.

The advisory later noted an integer-overflow scenario even when a buffer was large enough to avoid the heap overflow. It described the impact as limited because curl rejects control characters and nulls in a hostname; this is distinct from the original heap-overflow conditions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What was CVE-2023-38546, and did it affect the curl command line?

CVE-2023-38546 was a conditional cookie-handling issue in libcurl. It required an application to enable cookies and duplicate a libcurl easy handle. Under the conditions described in the advisory, the duplicate could retain the filename none without the source handle’s cookies. A later use could then load cookies from a readable file literally named none in the program’s current directory, if that file had the required cookie-file format.

The curl project rated this issue Low, citing the chain of prerequisites and low likelihood of harmful exploitation. The project stated: “This flaw is not accessible using the curl command line tool.” Applications embedding libcurl could still be relevant if they duplicated cookie-enabled handles and their working directory contained a suitable readable file named none.

Which versions were affected, and what fixed the flaws?

Issue Affected upstream versions Fixed upstream version Project severity
CVE-2023-38545, SOCKS5 heap buffer overflow libcurl 7.69.0 through 8.3.0 8.4.0 High
CVE-2023-38546, cookie handling libcurl 7.9.1 through 8.3.0 8.4.0 Low

These are the upstream version ranges and severity assessments in the curl project’s CVE-2023-38545 advisory and CVE-2023-38546 advisory, both published October 11, 2023. The advisories recommend upgrading or applying the relevant patch. For the cookie issue, the project also recommended clearing cookies after easy-handle duplication as a mitigation.

Version 8.4.0 is the historical first release containing these fixes, not a recommendation to run that version today. The curl project’s release table, checked September 30, 2026, lists 8.22.0 dated September 2, 2026. That upstream chronology does not establish the patch status of every operating-system or application package.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should you check whether your software needs attention?

  1. Identify the component. Determine whether you use the curl command-line tool, libcurl directly, or a product that bundles libcurl. Do not assume that finding a command named curl inventories every embedded copy.
  2. Check the package version and vendor advisory. Compare the upstream version against the affected ranges above, then check the operating-system or application vendor’s security notice and patch status. Vendors may deliver fixes through their own packages, so an upstream version number alone may not show the full status.
  3. Prioritize the SOCKS5 conditions. For CVE-2023-38545, review whether software used SOCKS5 remote hostname resolution, and whether its transfer buffer could be unset or below 65,541 bytes. For the command-line tool, also consider whether rate limiting reduced its normal buffer.
  4. Review cookie-handle use for CVE-2023-38546. For libcurl applications, check whether cookies were enabled, easy handles were duplicated, and a suitable readable file named none could be present in the program’s current working directory.
  5. Update or apply the vendor fix. Use a supported version supplied by the relevant operating-system or application vendor, or apply the applicable patch. If upgrading is not immediately possible for an application exposed to the cookie flaw, follow the advisory’s mitigation to clear cookies after handle duplication.

The curl advisories document these code-level conditions; they do not provide a universal list of affected products. An application inventory and the package maintainer’s security information are necessary to assess a particular deployment.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.