CVE-2024-2466: Apple macOS

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address, therefore completely skipping the certificate check. This affects all uses of TLS protocols (HTTPS, FTPS, IMAPS, POPS3, SMTPS, etc).

Affected products

  • Apple macOS: before 12.7.6 (fixed in 12.7.6); from 13.0, before 13.6.8 (fixed in 13.6.8); from 14.0, before 14.6 (fixed in 14.6)
  • Haxx Curl: from 8.5.0, before 8.7.0 (fixed in 8.7.0)
  • Netapp Bootstrap OS: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified

Published 2024-03-27. Last modified 2026-06-17.