Medium severity6.5NVD Advisory· Published Mar 27, 2024· Updated Jun 17, 2026
CVE-2024-2466
CVE-2024-2466
Description
libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- osv-coords16 versionspkg:apk/chainguard/curlpkg:apk/chainguard/curl-devpkg:apk/chainguard/curl-docpkg:apk/chainguard/curl-oci-entrypointpkg:apk/chainguard/curl-staticpkg:apk/chainguard/libcurl4pkg:apk/chainguard/libcurl-openssl4pkg:apk/wolfi/curlpkg:apk/wolfi/curl-devpkg:apk/wolfi/curl-docpkg:apk/wolfi/curl-oci-entrypointpkg:apk/wolfi/curl-staticpkg:apk/wolfi/libcurl4pkg:apk/wolfi/libcurl-openssl4pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Micro%206.0
< 8.7.1-r0+ 15 more
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-r0
- (no CPE)range: < 8.7.1-1.1
- (no CPE)range: < 8.6.0-3.1
Patches
Vulnerability mechanics
References
12- hackerone.com/reports/2416725nvdExploitIssue TrackingThird Party Advisory
- www.vicarius.io/vsociety/posts/tls-certificate-check-bypass-curl-with-mbedtls-cve-2024-2466-2468nvdExploitMitigationThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/18nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/19nvdMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/20nvdMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2024/03/27/4nvdMailing ListThird Party Advisory
- curl.se/docs/CVE-2024-2466.htmlnvdVendor Advisory
- curl.se/docs/CVE-2024-2466.jsonnvdVendor Advisory
- security.netapp.com/advisory/ntap-20240503-0010/nvdThird Party Advisory
- support.apple.com/kb/HT214118nvdRelease NotesVendor Advisory
- support.apple.com/kb/HT214119nvdRelease NotesVendor Advisory
- support.apple.com/kb/HT214120nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.