The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →curl and libcurl versions through 8.3.0 were affected by two security flaws fixed in curl 8.4.0, released October 11, 2023. The higher-risk issue, CVE-2023-38545, is a heap buffer overflow involving SOCKS5 proxy hostname handling; CVE-2023-38546 can cause cookie injection in certain libcurl applications that duplicate cookie-enabled handles. If you still run an affected version, upgrade to a current vendor-supported package and check whether its security update was backported.
At a glance: what is affected?
| Flaw | Affected component and versions | Trigger and impact | Severity |
|---|---|---|---|
| CVE-2023-38545 | libcurl 7.69.0 through 8.3.0; the curl command-line tool is affected only under particular conditions | SOCKS5 remote-hostname handling can overflow a heap buffer | High; CVSS 7.5 reported by The Hacker News in 2023 |
| CVE-2023-38546 | libcurl 7.9.1 through 8.3.0; not reachable through the curl command-line tool | Duplicating a cookie-enabled handle can enable unintended cookie injection | Low; CVSS 5.0 reported by The Hacker News in 2023 |
Both upstream advisories were published October 11, 2023, and both fixes shipped in curl 8.4.0 that day. The project’s CVE-2023-38545 advisory, CVE-2023-38546 advisory, and curl 8.4.0 release notes document the issues and fixes.
Is this curl or libcurl?
curl is the command-line program; libcurl is the library that applications can link to for transferring data. Updating the curl executable does not necessarily update the libcurl library used by every other program on the system. Conversely, a vendor may update or patch the library package independently of the command-line tool.
Check both the executable and the packages or applications that use libcurl. The upstream project notes that libcurl is embedded in many applications and may not be obvious from an application’s name or interface. On operating systems that backport security fixes, an older upstream version string alone may not show whether the installed package is vulnerable: consult the vendor’s security notice and verify the runtime package.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
CVE-2023-38545: SOCKS5 heap buffer overflow
The curl project describes CVE-2023-38545 as a heap-based buffer overflow in the SOCKS5 proxy handshake. The affected versions are libcurl 7.69.0 through 8.3.0; versions before 7.69.0 and versions 8.4.0 or later are not affected according to the advisory. The project rates the issue High and classifies it as CWE-122.
How the flaw can be triggered
A hostname longer than 255 bytes can cause curl to switch from asking a SOCKS5 proxy to resolve the hostname to resolving it locally. In a slow proxy handshake, a faulty state flag can leave curl attempting remote resolution and copying the oversized hostname into a heap buffer that cannot hold it. The hostname can come from a URL, and a crafted redirect may help supply one.
Rank #2
When the curl tool is exposed
The curl command-line tool’s default 100 kB download buffer generally protects it from the conditions needed for this flaw. It can become vulnerable if the user configures a lower transfer-rate limit. By contrast, libcurl applications can be exposed when they use SOCKS5 remote-hostname mode—such as socks5h:// or CURLPROXY_SOCKS5_HOSTNAME—and the relevant buffer conditions are present. This is not a claim that every curl or libcurl use is exploitable.
CVE-2023-38546: cookie injection through a duplicated handle
CVE-2023-38546 affects libcurl 7.9.1 through 8.3.0 and is fixed in 8.4.0. The curl project rates it Low and classifies it as CWE-73. It is not reachable through the curl command-line tool; the risk concerns applications that use libcurl’s cookie and handle-duplication features.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
Why duplication can matter
When an application duplicates a cookie-enabled easy handle with curl_easy_duphandle, the duplicate inherits the cookie-enabled state but not the cookies themselves. If no cookie file had been read, the duplicate can be left with the literal filename none. If a file named none exists in the process’s current directory and has the expected cookie-file format, later use can read it and allow unintended cookies to be injected into the running program.
How to patch or mitigate the flaws
- Upgrade: Install curl and libcurl 8.4.0 or newer, preferably through your operating system or software vendor’s supported package channel. If the package retains an older version string, check the vendor’s advisory for backported fixes.
- If upgrading is blocked: Apply the relevant upstream patch and rebuild the affected software. The upstream advisories provide the fix information for CVE-2023-38545 and CVE-2023-38546.
- For CVE-2023-38545: Until patched, avoid SOCKS5 remote-hostname mode: do not use
socks5h://,CURLPROXY_SOCKS5_HOSTNAME, or equivalent proxy environment settings in affected software. - For CVE-2023-38546: If you cannot upgrade, the advisory’s interim recommendation is to clear cookies on each duplicated handle by calling
curl_easy_setopt(cloned_curl, CURLOPT_COOKIELIST, "ALL")aftercurl_easy_duphandle(). - Inventory installations: Check the curl executable and separately identify services, desktop applications, or other software that links libcurl. Confirm the version or vendor fix status of the library actually loaded at runtime.
Should you update curl 8.3.0?
Yes. Upstream lists 8.3.0 as affected by both flaws, so move to 8.4.0 or newer, or confirm that your vendor has supplied a package with the fixes backported. The release date for 8.4.0 was October 11, 2023; use a currently supported vendor package rather than treating that historical release as a recommendation to stop at 8.4.0.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

