PT-2024-2654 · Libcurl+2 · Libcurl+2

Daniel Stenberg

+2

·

Published

2024-03-10

·

Updated

2026-06-05

·

CVE-2024-2379

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions libcurl versions (affected versions not specified)
Description The issue is related to libcurl skipping certificate verification for a QUIC connection under certain conditions when built to use wolfSSL. If an unknown or bad cipher or curve is used, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems. This could allow a remote attacker to ignore any certificate issues.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

AZL-42966
BDU:2024-02721
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2024-2379
ECHO-B0DE-6C4F-E1FD
JLSEC-2026-415
MGASA-2024-0099
OPENSUSE-SU-2024:13805-1
RHSA-2024:2693
SUSE-SU-2025:20029-1

Affected Products

Debian
Apple Macos
Libcurl