VDB

GCVE-VVD-MAGEIA-2024-79

GCVE-VVD-MAGEIA-2024-79
Advisory Published
Vulnetix · Advisory published February 28, 2024
It was discovered that the uv_getaddrinfo() function in libuv, an asynchronous event notification library, incorrectly truncated certain hostnames, which may result in bypass of security measures on internal APIs or SSRF attacks. (CVE-2024-24806)

Affected Products

VendorProductVersionsPlatforms
Mageiaopencontainers-runc0 (affected), 1.1.9-1.mga9 (unaffected)
Mageialibuv0 (affected), 1.44.2-2.1.mga9 (unaffected), 0 (affected), 1.44.2-2.1.mga9 (unaffected)

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›