Medium severity6.5NVD Advisory· Published Sep 11, 2024· Updated Jun 17, 2026
CVE-2024-8096
CVE-2024-8096
Description
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31- osv-coords30 versionspkg:apk/chainguard/curlpkg:apk/chainguard/curl-devpkg:apk/chainguard/curl-docpkg:apk/chainguard/curl-oci-entrypointpkg:apk/chainguard/curl-staticpkg:apk/chainguard/libcurl4pkg:apk/chainguard/libcurl-openssl4pkg:apk/wolfi/curlpkg:apk/wolfi/curl-devpkg:apk/wolfi/curl-docpkg:apk/wolfi/curl-oci-entrypointpkg:apk/wolfi/curl-staticpkg:apk/wolfi/libcurl4pkg:apk/wolfi/libcurl-openssl4pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/curl&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/opensuse/curl&distro=openSUSE%20Tumbleweedpkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Installer%20Updates%2015%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/curl&distro=SUSE%20Linux%20Micro%206.1
< 8.10.0-r0+ 29 more
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.10.0-r0
- (no CPE)range: < 8.0.1-150400.5.50.1
- (no CPE)range: < 8.6.0-150600.4.6.1
- (no CPE)range: < 8.0.1-150400.5.50.1
- (no CPE)range: < 8.10.0-1.1
- (no CPE)range: < 8.0.1-150400.5.50.1
- (no CPE)range: < 7.66.0-150200.4.78.1
- (no CPE)range: < 7.66.0-150200.4.78.1
- (no CPE)range: < 8.0.1-150400.5.50.1
- (no CPE)range: < 8.0.1-150400.5.50.1
- (no CPE)range: < 8.0.1-150400.5.50.1
- (no CPE)range: < 8.0.1-150400.5.50.1
- (no CPE)range: < 8.6.0-150600.4.6.1
- (no CPE)range: < 8.0.1-11.92.1
- (no CPE)range: < 8.0.1-11.92.1
- (no CPE)range: < 8.0.1-11.92.1
- (no CPE)range: < 8.12.1-slfo.1.1_1.1
Patches
Vulnerability mechanics
References
6- hackerone.com/reports/2669852nvdExploitIssue TrackingThird Party Advisory
- www.openwall.com/lists/oss-security/2024/09/11/1nvdMailing ListThird Party Advisory
- curl.se/docs/CVE-2024-8096.htmlnvdVendor Advisory
- curl.se/docs/CVE-2024-8096.jsonnvdVendor Advisory
- lists.debian.org/debian-lts-announce/2024/11/msg00008.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20241011-0005/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.