GHSA-94rh-gwj6-33j3
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 29, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.