curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to
the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.
the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 20 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: curl
Published:
Updated: 2025-06-20T20:04:09.066Z
Reserved: 2024-01-24T08:42:02.618Z
Link: CVE-2024-0853

Updated: 2024-08-01T18:18:19.012Z

Status : Modified
Published: 2024-02-03T14:15:50.850
Modified: 2025-06-20T20:15:27.820
Link: CVE-2024-0853


No data.