CVE-2024-8096 describes a flaw in curl's OCSP stapling verification, where it may incorrectly validate server certificates if the OCSP response indicates an error other than 'revoked'. This vulnerability affects products utilizing curl, including Debian, Haxx, and NetApp. With a CVSS score of 6.5 (Medium), it presents a network-based attack vector with low complexity, potentially leading to unauthorized access or information disclosure. There is currently no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.41.0, < 8.10.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* | ||
10CPE matchmatch criteria | cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
curl vulnerabilities
Jul 9, 2026Third-Party Package Updates in Splunk Enterprise - July 2025
Jul 7, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025CVE-2024-8096
Nov 12, 2024CVE-2024-8096
Oct 8, 2024OCSP stapling bypass with GnuTLS
Sep 11, 2024curl: OCSP stapling bypass with GnuTLS
Sep 11, 2024OCSP stapling bypass with GnuTLS
Sep 10, 2024