{"id":"JLSEC-2026-1342","summary":"When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed...","details":"When curl retrieves an HTTP response, it stores the incoming headers so that\nthey can be accessed later via the libcurl headers API.\n\nHowever, curl did not have a limit in how many or how large headers it would\naccept in a response, allowing a malicious server to stream an endless series\nof headers and eventually cause curl to run out of heap memory.","modified":"2026-08-17T13:44:05.759306517Z","published":"2026-08-17T13:15:13.400Z","upstream":["CVE-2023-38039","EUVD-2023-41865","GHSA-99j9-jf36-9747"],"database_specific":{"sources":[{"html_url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38039","database_specific":{"status":"Modified"},"id":"CVE-2023-38039","imported":"2026-08-16T08:05:13.277Z","modified":"2026-06-17T06:09:17.450Z","published":"2023-09-15T04:15:10.127Z","url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2023-38039"},{"id":"GHSA-99j9-jf36-9747","imported":"2026-08-16T08:06:45.398Z","modified":"2024-04-01T18:30:56Z","published":"2023-09-15T06:30:18Z","url":"https://api.github.com/advisories/GHSA-99j9-jf36-9747","html_url":"https://github.com/advisories/GHSA-99j9-jf36-9747"},{"url":"https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2023-41865","html_url":"https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-41865","id":"EUVD-2023-41865","imported":"2026-08-16T08:06:26.884Z","modified":"2025-12-02T20:06:21Z","published":"2023-09-15T03:21:54Z"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2023/Oct/17"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Jan/34"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Jan/37"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Jan/38"},{"type":"WEB","url":"https://github.com/advisories/GHSA-99j9-jf36-9747"},{"type":"WEB","url":"https://hackerone.com/reports/2072338"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5DCZMYODALBLVOXVJEN2LF2MLANEYL4F"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5DCZMYODALBLVOXVJEN2LF2MLANEYL4F/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M6KGKB2JNZVT276JYSKI6FV2VFJUGDOJ"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M6KGKB2JNZVT276JYSKI6FV2VFJUGDOJ/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEAWTYHC3RT6ZRS5OZRHLAIENVN6CCIS"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEAWTYHC3RT6ZRS5OZRHLAIENVN6CCIS/"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38039"},{"type":"WEB","url":"https://security.gentoo.org/glsa/202310-12"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20231013-0005"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20231013-0005/"},{"type":"WEB","url":"https://support.apple.com/kb/HT214036"},{"type":"WEB","url":"https://support.apple.com/kb/HT214057"},{"type":"WEB","url":"https://support.apple.com/kb/HT214058"},{"type":"WEB","url":"https://support.apple.com/kb/HT214063"},{"type":"WEB","url":"https://www.insyde.com/security-pledge/SA-2023064"}],"affected":[{"package":{"name":"LibCURL_jll","ecosystem":"Julia","purl":"pkg:julia/LibCURL_jll?uuid=deac9b47-8bc7-5906-a0fe-35ac56dc84c0"},"ranges":[{"type":"SEMVER","events":[{"introduced":"7.84.0+0"},{"fixed":"8.4.0+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1342.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","source":"NVD"}]}