CVE-2024-24783 is a flaw in Go's crypto/x509 standard-library package. Certificate.Verify panics when verifying a certificate chain that contains a certificate using an unknown public-key algorithm. The flaw affects crypto/tls clients that verify such chains and TLS servers configured to verify client certificates with Config.ClientAuth set to VerifyClientCertIfGiven or RequireAndVerifyClientCert. Default Go TLS server configurations are not affected because they do not verify client certificates.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
34 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go crypto/x509 vulnerability in which certificate verification can panic when processing certificates with an unknown public-key algorithm.
Go crypto/x509 denial-of-service flaw: certificate verification can panic on a certificate using an unknown public-key algorithm, affecting crypto/tls clients and TLS servers configured to verify client certificates.
Unknown
Panic vulnerability in Go crypto/x509 certificate verification when processing certificates using an unknown public-key algorithm.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.