CVE-2023-38434: Xhttp Project Xhttp

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.

Affected products

Published 2023-07-18. Last modified 2026-06-17.