PT-2023-8494 · Curl+2 · Curl+2

Daniel Stenberg

+2

·

Published

2023-12-29

·

Updated

2026-05-18

·

CVE-2024-0853

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions curl (affected versions not specified)
Description The issue is related to a flaw in curl where it inadvertently keeps the SSL session ID for connections in its cache even when the verify status (OCSP stapling) test failed. This allows a subsequent transfer to the same hostname to succeed if the session ID cache is still fresh, skipping the verify status check. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

ALT-PU-2024-1624
ALT-PU-2024-1813
ALT-PU-2024-2266
ALT-PU-2024-4175
AZL-34061
AZL-34648
BDU:2024-01014
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2024-0853
JLSEC-2026-412
OPENSUSE-SU-2024:13637-1
ROSA-SA-2025-2567

Affected Products

Alt Linux
Ibm Aix
Curl