CVE-2024-8096
published 2024-09-11CVE-2024-8096: When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.73%
50.4th percentile
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
Affected
114 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 7.41.0 – 7.41.0 | — |
| curl | curl | 7.42.0 – 7.42.0 | — |
| curl | curl | 7.42.1 – 7.42.1 | — |
| curl | curl | 7.43.0 – 7.43.0 | — |
| curl | curl | 7.44.0 – 7.44.0 | — |
| curl | curl | 7.45.0 – 7.45.0 | — |
| curl | curl | 7.46.0 – 7.46.0 | — |
| curl | curl | 7.47.0 – 7.47.0 | — |
| curl | curl | 7.47.1 – 7.47.1 | — |
| curl | curl | 7.48.0 – 7.48.0 | — |
| curl | curl | 7.49.0 – 7.49.0 | — |
| curl | curl | 7.49.1 – 7.49.1 | — |
| curl | curl | 7.50.0 – 7.50.0 | — |
| curl | curl | 7.50.1 – 7.50.1 | — |
| curl | curl | 7.50.2 – 7.50.2 | — |
| curl | curl | 7.50.3 – 7.50.3 | — |
| curl | curl | 7.51.0 – 7.51.0 | — |
| curl | curl | 7.52.0 – 7.52.0 | — |
| curl | curl | 7.52.1 – 7.52.1 | — |
| curl | curl | 7.53.0 – 7.53.0 | — |
| curl | curl | 7.53.1 – 7.53.1 | — |
| curl | curl | 7.54.0 – 7.54.0 | — |
| curl | curl | 7.54.1 – 7.54.1 | — |
| curl | curl | 7.55.0 – 7.55.0 | — |
| curl | curl | 7.55.1 – 7.55.1 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_oracle6.5MEDIUM
vendor_redhat6.5MEDIUM
vendor_ubuntu3.4LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
curl vulnerabilities
vendor_ubuntu·2026-07-09·CVSS 3.4
CVE-2026-11352 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Harry Sintonen discovered that curl incorrectly handled credentials when
following HTTP redirects in conjunction with .netrc files. An attacker
could possibly use this issue to obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.
(CVE-2024-11053)
Hiroki Kurosawa discovered that curl incorrectly handled OCSP stapling
responses. A remote attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2024-8096)
Joshua Rogers discovered that curl had a use-after-free vulnerability when
resetting and cleaning up HTTP/2 stream handles. An attacker could possibly
use this issue
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Mod_Security (curl) — CVE-2024-8096
vendor_oracle·2025-01-15·CVSS 6.5
CVE-2024-8096 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Mod_Security (curl) — CVE-2024-8096
Oracle Oracle Fusion Middleware Risk Matrix: Mod_Security (curl) vulnerability
CVE: CVE-2024-8096
CVSS: 6.5
Protocol: TLS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2025 (JAN 2025)
Ubuntu
curl vulnerability
vendor_ubuntu·2024-09-16
CVE-2024-8096 curl vulnerability
Title: curl vulnerability
Summary: curl could incorrectly check bad certificates when OCSP stapling is in use.
Hiroki Kurosawa discovered that curl incorrectly handled certain OCSP
responses. This could result in bad certificates not being checked
properly, contrary to expectations.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
curl: OCSP stapling bypass with GnuTLS
vendor_redhat·2024-09-11·CVSS 6.5
CVE-2024-8096 [MEDIUM] CWE-295 curl: OCSP stapling bypass with GnuTLS
curl: OCSP stapling bypass with GnuTLS
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
A vulnerability was found in Curl. When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and incorrectly consider the response as fine instead. If the returned status reports an error other than "revoked", such as "unauthorized", it
Microsoft
OCSP stapling bypass with GnuTLS
vendor_msrc·2024-09-10·CVSS 6.5
CVE-2024-8096 [MEDIUM] CWE-295 OCSP stapling bypass with GnuTLS
OCSP stapling bypass with GnuTLS
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
curl: curl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azur
Debian
CVE-2024-8096: curl - When curl is told to use the Certificate Status Request TLS extension, often ref...
vendor_debian·2024·CVSS 6.5
CVE-2024-8096 [MEDIUM] CVE-2024-8096: curl - When curl is told to use the Certificate Status Request TLS extension, often ref...
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
Scope: local
bookworm: resolved (fixed in 7.88.1-10+deb12u8)
bullseye: resolved (fixed in 7.74.0-1.3+deb11u14)
forky: resolved (fixed in 8.10.0-1)
sid: resolved (fixed in 8.10.0-1)
trixie: resolved (fixed in 8.10.0-1)
OSV
CVE-2024-8096: When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is va
osv·2024-09-11·CVSS 6.5
CVE-2024-8096 [MEDIUM] CVE-2024-8096: When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is va
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
GHSA
GHSA-gv3v-x3f3-7fxm: When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is va
ghsa_unreviewed·2024-09-11
CVE-2024-8096 [MEDIUM] CWE-295 GHSA-gv3v-x3f3-7fxm: When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is va
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.
GHSA
Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
ghsa·2024-07-31
CVE-2024-41950 [HIGH] CWE-1336 Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
Insecure Jinja2 templates rendered in Haystack Components can lead to RCE
### Impact
Haystack clients that let their users create and run Pipelines from scratch are vulnerable to remote code executions.
Certain Components in Haystack use Jinja2 templates, if anyone can create and render that template on the client machine they run any code.
### Patches
The problem has been fixed with PRs deepset-ai/haystack#8095 and deepset-ai/haystack#8096.
Both have been released with Haystack `2.3.1`.
### Workarounds
Prevent users from running the affected Components, or only let users use preselected templates.
### References
The list of impacted Components can be found in the release notes for `2.3.1`.
https://github.com/deepset-ai/haystack/releases/tag/v2.3.1
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2024-8096: OCSP stapling bypass with GnuTLS
hackerone·2024-09-11·CVSS 6.5
CVE-2024-8096 [MEDIUM] CVE-2024-8096: OCSP stapling bypass with GnuTLS
CVE-2024-8096: OCSP stapling bypass with GnuTLS
## Summary:
When the TLS backend is GnuTLS, there is an issue with the OCSP stapling validation process. As a result, even if the certificate is revoked, the connection can be established without resulting in an error.
When the OCSP stapling status response is "revoked," gnutls_certificate_verify_peers2() returns an error. However, gnutls_certificate_verify_peers2() only returns an error when the OCSP status is "revoked." For other statuses, gnutls_certificate_verify_peers2() returns a successful result.
In curl, the verification of the OCSP stapling status response is performed not only with the above function but also with gnutls_ocsp_status_request_is_checked(). However, this function returns a non-zero value if the OCSP stapling status
Bugzilla
CVE-2024-8096 curl: OCSP stapling bypass with GnuTLS
bugzilla·2024-09-06·CVSS 6.5
CVE-2024-8096 [MEDIUM] CVE-2024-8096 curl: OCSP stapling bypass with GnuTLS
CVE-2024-8096 curl: OCSP stapling bypass with GnuTLS
This issue only exists when curl is built to use the GnuTLS library. curl can
be made to use a large variety of TLS libraries and GnuTLS is not the most
common choice.
OCSP stapling is not a widely used feature on the open web, perhaps partly
because so many big name sites do not support it.
This bug is **not** considered a *C mistake* (likely to have been avoided had
we not been using C).
This flaw also affects the curl command line tool.
2024-09-11
Published