Sploitus

CVE-2024-0853

No indexed exploits for CVE-2024-0853 yet

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.

Affected products
Alt Linux, Ibm Aix, Curl
Haxx Curl
= 8.5.0
CVSS 3.1
5.3 MEDIUM
EPSS
1.1% (63th percentile)
Weakness
CWE-295
NVD status
Modified
Published
2024-02-03
CVE-2024-0853 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-0853 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-0853 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.