Total vulnerabilities in the database
curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (OCSP stapling) test failed. A subsequent transfer to the same hostname could then succeed if the session ID cache was still fresh, which then skipped the verify status check.
Software | From | Fixed in |
---|---|---|
haxx / curl | 8.5.0 | 8.5.0.x |