Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-0853

19
FAUCET Score

CVE-2024-0853 is a medium-severity vulnerability affecting haxx curl, where curl incorrectly cached SSL session IDs even after OCSP stapling verification failed. This allowed subsequent connections to the same hostname to bypass certificate status checks, potentially enabling an attacker to serve an invalid certificate without detection. The vulnerability has a CVSS score of 5.3, indicating a network-based attack with low complexity and a potential impact of low integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has received some community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.5.0, <= 8.5.0CPE match
cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:*
8.5.0CPE matchmatch criteria
cpe:2.3:a:haxx:curl:8.5.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.10%
Probability of exploitation in next 30 days
EPSS Percentile
62.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0110 is in the 40th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

hikvisionpatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: azl3 curl 8.5.0-1 on Azure Linux 3.0Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: 17271-16823Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: 17629-17084Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: 19736-17086Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: 19742-17084Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: cbl2 curl 8.8.0-1 on CBL Mariner 2.0Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: azl3 curl 8.8.0-1 on Azure Linux 3.0Fixed in: 8.8.0-1
microsoftpatch availablevia msrc
Product: cbl2 curl 8.5.0-2 on CBL Mariner 2.0Fixed in: 8.8.0-1
nodejspatch availablevia llm_extracted
Fixed in: 9.4.3, 9.3.5, 9.2.7, 9.1.10

Vendor Advisories (5)

nodejsllm-nodejs-b263506120f02d37CRITICAL

Third-Party Package Updates in Splunk Enterprise - July 2025

Jul 7, 2025
microsoft2024-Sep/CVE-2024-0853

CVE-2024-0853

Sep 10, 2024
microsoft2024-Feb/CVE-2024-0853Moderate

OCSP verification bypass with TLS session reuse

Feb 13, 2024
redhatCVE-2024-0853Low

curl: OCSP verification bypass with TLS session reuse

Jan 31, 2024
hikvisionllm-hikvision-0a11e880f993c7edLOW

OCSP verification bypass with TLS session reuse

Jan 31, 2024

References

curl.se / docs/CVE-2024-0853.html
Vendor Advisory
curl.se / docs/CVE-2024-0853.json
Vendor Advisory
hackerone.com / reports/2298922
ExploitIssue Tracking
security.netapp.com / advisory/ntap-20240307-0004
security.netapp.com / advisory/ntap-20240426-0009
security.netapp.com / advisory/ntap-20240503-0012