{"id":"CVE-2024-0853","summary":"OCSP verification bypass with TLS session reuse","details":"curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent transfer to\nthe same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.","aliases":["CURL-CVE-2024-0853"],"modified":"2026-08-12T03:51:20.094247781Z","published":"2024-02-03T13:35:25.863Z","related":["CGA-jhf8-hfv6-c8cj","openSUSE-SU-2024:13637-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0853.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.5.0"},{"last_affected":"8.5.0"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"curl"},"references":[{"type":"WEB","url":"https://curl.se/docs/CVE-2024-0853.html"},{"type":"WEB","url":"https://curl.se/docs/CVE-2024-0853.json"},{"type":"WEB","url":"https://hackerone.com/reports/2298922"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0853.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0853"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240307-0004/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240426-0009/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240503-0012/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/curl/curl","events":[{"introduced":"7161cb17c01dcff1dc5bf89a18437d9d729f1ecd"},{"last_affected":"7161cb17c01dcff1dc5bf89a18437d9d729f1ecd"}],"database_specific":{"extracted_events":[{"introduced":"8.5.0"},{"last_affected":"8.5.0"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:haxx:curl:8.5.0:*:*:*:*:*:*:*"}}],"versions":["8.5.0","curl-8_5_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-0853.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}