Skip to main content


CVE-2024-5535 is an #OpenSSL problem that cannot be triggered by #curl

OpenSSL calls it it a low severity flaw. openssl.org/news/vulnerabiliti…

GitHub lists it as "critical" at 9.1 out of 10: github.com/advisories/GHSA-4fc…

This entry was edited (4 months ago)
in reply to daniel:// stenberg://

It is time we realize and accept that there can never be a single nor objective criticality score for a CVE.
in reply to daniel:// stenberg://

Speaking as someone who is dealing with that as a OSS project member live-and-direct-this-instant, I couldn't agree more.

We're not a CNA (nor are we particularly bothered in becoming one), and as you've noted that doesn't do much to stop the garbage.

in reply to daniel:// stenberg://

ya, I have been fighting the battle that a CVE has a community context (general) and a specific context to any bit of software .. its the main issue with CVE that someone else's 9.1 will be one's 0 ... a community score vs a specific software score is needed to provide context