Medium severity5.3NVD Advisory· Published Feb 3, 2024· Updated Jun 17, 2026
CVE-2024-0853
CVE-2024-0853
Description
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- osv-coords15 versionspkg:apk/chainguard/curlpkg:apk/chainguard/curl-devpkg:apk/chainguard/curl-docpkg:apk/chainguard/curl-oci-entrypointpkg:apk/chainguard/curl-staticpkg:apk/chainguard/libcurl4pkg:apk/chainguard/libcurl-openssl4pkg:apk/wolfi/curlpkg:apk/wolfi/curl-devpkg:apk/wolfi/curl-docpkg:apk/wolfi/curl-oci-entrypointpkg:apk/wolfi/curl-staticpkg:apk/wolfi/libcurl4pkg:apk/wolfi/libcurl-openssl4pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweed
< 8.6.0-r0+ 14 more
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-r0
- (no CPE)range: < 8.6.0-1.1
Patches
Vulnerability mechanics
References
6- hackerone.com/reports/2298922nvdExploitIssue Tracking
- curl.se/docs/CVE-2024-0853.htmlnvdVendor Advisory
- curl.se/docs/CVE-2024-0853.jsonnvdVendor Advisory
- security.netapp.com/advisory/ntap-20240307-0004/nvd
- security.netapp.com/advisory/ntap-20240426-0009/nvd
- security.netapp.com/advisory/ntap-20240503-0012/nvd
News mentions
0No linked articles in our index yet.