{"schema_version":"1.9.0","id":"CVE-2024-2379","published":"2024-03-27T07:56:41.158Z","modified":"2026-08-12T03:51:11.642811593Z","aliases":["CURL-CVE-2024-2379"],"related":["CGA-6rjf-f6x6-r857","SUSE-SU-2025:20029-1","openSUSE-SU-2024:13805-1"],"summary":"QUIC certificate check bypass with wolfSSL","details":"libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/curl/curl","events":[{"introduced":"5ce164e0e9290c96eb7d502173426c0a135ec008"},{"last_affected":"5ce164e0e9290c96eb7d502173426c0a135ec008"}],"database_specific":{"cpe":"cpe:2.3:a:haxx:curl:8.6.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"8.6.0"},{"last_affected":"8.6.0"}],"source":"CPE_STRING"}}],"versions":["8.6.0","curl-8_6_0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-2379.json"}}],"references":[{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Jul/18"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Jul/19"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2024/Jul/20"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2024/03/27/2"},{"type":"WEB","url":"https://curl.se/docs/CVE-2024-2379.html"},{"type":"WEB","url":"https://curl.se/docs/CVE-2024-2379.json"},{"type":"WEB","url":"https://hackerone.com/reports/2410774"},{"type":"WEB","url":"https://support.apple.com/kb/HT214118"},{"type":"WEB","url":"https://support.apple.com/kb/HT214119"},{"type":"WEB","url":"https://support.apple.com/kb/HT214120"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2379.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-2379"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240531-0001/"}],"database_specific":{"cna_assigner":"curl","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/2xxx/CVE-2024-2379.json","unresolved_ranges":[{"extracted_events":[{"introduced":"8.6.0"},{"last_affected":"8.6.0"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"}]}