Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-7264

30
FAUCET Score

CVE-2024-7264 is a vulnerability in haxx libcurl's ASN.1 parser, specifically within the GTime2str() function. An improperly formatted ASN.1 Generalized Time field can cause the parser to attempt a strlen() operation on a non-null-terminated heap buffer, leading to a crash or the disclosure of heap contents if CURLINFO_CERTINFO is used. This medium-severity vulnerability (CVSS 6.5) requires user interaction (UI:R) and could result in a denial of service (A:H) or information disclosure (C:N). There is currently no evidence of active exploitation, public exploit code, or significant community discussion, with only one article mentioning it.

Impacted Technologies

VendorProductVersion(s)CPE
>= 7.32.0, < 8.9.1CPE matchmatch criteria
cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*
>= 7.32.0, <= 7.32.0CPE match
cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:*
>= 7.33.0, <= 7.33.0CPE match
cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:*
>= 7.34.0, <= 7.34.0CPE match
cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:*
>= 7.35.0, <= 7.35.0CPE match
cpe:2.3:a:curl:curl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
17.30%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1730 is in the 99th percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (52)

hikvisionpatch availablevia llm_extracted
microsoftpatch availablevia msrc
Product: 17464-17084Fixed in: 3.30.3-4
microsoftpatch availablevia msrc
Product: 19690-17084Fixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: 17235-17086Fixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: 19677-17086Fixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: 17579-17084Fixed in: 8.11.1-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 8.0.40-2
microsoftpatch availablevia msrc
Product: 17578-17084Fixed in: 3.30.3-4
microsoftpatch availablevia msrc
Product: 17269-16823Fixed in: 1.68.0-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 8.0.40-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: azl3 curl 8.8.0-4 on Azure Linux 3.0Fixed in: 8.11.1-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: cbl2 mysql 8.0.36-1 on CBL Mariner 2.0Fixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: azl3 mysql 8.0.36-1 on Azure Linux 3.0Fixed in: 8.0.40-1
microsoftpatch availablevia msrc
Product: azl3 cmake 3.30.3-6 on Azure Linux 3.0Fixed in: 3.30.3-4
microsoftpatch availablevia msrc
Product: azl3 cmake 3.30.3-4 on Azure Linux 3.0Fixed in: 3.30.3-4
microsoftpatch availablevia msrc
Product: cbl2 rust 1.68.0-1 on CBL Mariner 2.0Fixed in: 1.68.0-1
nodejspatch availablevia llm_extracted
View patch
nodejspatch availablevia llm_extracted
Fixed in: 9.4.3, 9.3.5, 9.2.7, 9.1.10
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/pilot-rhel8:2.6.2-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: mysql:8.0-8100020250212154709.489197e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: mysql-0:8.0.41-2.el9_5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/grafana-rhel8:2.6.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/istio-cni-rhel8:2.6.2-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/istio-must-gather-rhel8:2.6.2-4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/istio-rhel8-operator:2.6.2-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/kiali-ossmc-rhel8:1.89.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/kiali-rhel8:1.89.4-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/kiali-rhel8-operator:1.89.6-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 8Fixed in: openshift-service-mesh/ratelimit-rhel8:2.6.2-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Service Mesh 2.6 for RHEL 9Fixed in: openshift-service-mesh/proxyv2-rhel9:2.6.2-7
View patch
applevendor investigatingvia apple_support
View patch
barracudavendor investigatingvia llm_extracted
boschvendor investigatingvia llm_extracted
clamavvendor investigatingvia llm_extracted
consulvendor investigatingvia llm_extracted
freshrssvendor investigatingvia llm_extracted
qdrantvendor investigatingvia llm_extracted
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: curl
redhatvendor investigatingvia redhat_api
Product: Red Hat JBoss Core ServicesFixed in: jbcs-httpd24-curl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: curl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: curl
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: curl
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
symantecvendor investigatingvia llm_extracted
verbbvendor investigatingvia llm_extracted
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: mysql8.4
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: curl

Vendor Advisories (25)

nodejsllm-nodejs-b263506120f02d37CRITICAL

Third-Party Package Updates in Splunk Enterprise - July 2025

Jul 7, 2025
microsoft2024-Dec/CVE-2024-7264

CVE-2024-7264

Dec 10, 2024
microsoft2024-Nov/CVE-2024-7264

CVE-2024-7264

Nov 12, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
microsoft2024-Oct/CVE-2024-7264

CVE-2024-7264

Oct 8, 2024
verbbllm-verbb-7982d932b520b88d

Curl advisory

Aug 26, 2024
symantecllm-symantec-c4089f67e819cf63

Curl advisory

Aug 26, 2024
barracudallm-barracuda-be29ffa79447eaba

Curl advisory

Aug 26, 2024
qdrantllm-qdrant-1798f2f21c950eee

Curl advisory

Aug 26, 2024
freshrssllm-freshrss-b4605d63120c36c1

Curl advisory

Aug 26, 2024
boschllm-bosch-d67199d92c7c2014

Curl advisory

Aug 26, 2024
clamavllm-clamav-dbc81d0dd103240d

Curl advisory

Aug 26, 2024
consulllm-consul-2fba745586d0e5a9

Curl advisory

Aug 26, 2024
redhatCVE-2024-7264Low

curl: libcurl: ASN.1 date parser overread

Jul 31, 2024
hikvisionllm-hikvision-20456348c5ef3001LOW

ASN.1 date parser overread

Jul 31, 2024
microsoft2024-Jul/CVE-2024-7264Moderate

ASN.1 date parser overread

Jul 9, 2024
appleapple:125891LOW

About the security content of visionOS 26.2 - Apple Support

appleapple:125890LOW

About the security content of watchOS 26.2 - Apple Support

appleapple:125885LOW

About the security content of iOS 18.7.3 and iPadOS 18.7.3 - Apple Support

appleapple:125889LOW

About the security content of tvOS 26.2 - Apple Support

appleapple:125888LOW

About the security content of macOS Sonoma 14.8.3 - Apple Support

appleapple:125887LOW

About the security content of macOS Sequoia 15.7.3 - Apple Support

appleapple:125886LOW

About the security content of macOS Tahoe 26.2 - Apple Support

appleapple:125884LOW

About the security content of iOS 26.2 and iPadOS 26.2 - Apple Support

References

curl.se / docs/CVE-2024-7264.html
Vendor Advisory
curl.se / docs/CVE-2024-7264.json
Vendor Advisory
hackerone.com / reports/2629968
ExploitIssue TrackingPermissions RequiredThird Party Advisory
openwall.com / lists/oss-security/2024/07/31/1
Mailing List
github.com / curl/curl/commit/27959ecce75cdb2809c0bdb3286e60e08fadb519
security.netapp.com / advisory/ntap-20240828-0008
security.netapp.com / advisory/ntap-20241025-0006
security.netapp.com / advisory/ntap-20241025-0010