CVE-2024-5535 is a buffer over-read in OpenSSL's SSL_select_next_proto API. When an application calls the function with a zero-length client protocol list, the function does not detect the empty input and returns a pointer immediately following the client-list pointer while reporting no protocol overlap. Applications that use this invalid pointer can crash or transmit adjacent process memory to a peer. The issue is principally relevant to incorrectly implemented or configured ALPN/NPN negotiation callbacks; normal ALPN operation supplies a non-empty client protocol list through libssl.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2024-5535, a buffer overread vulnerability in OpenSSL's NPN (Next Protocol Negotiation) extension. The main file, 'CVE-2024-5535.py', is a Python script that allows a user to specify a target host and port (defaulting to 443) and attempts to exploit the vulnerability by negotiating NPN with the server. The script first checks if the target supports ALPN or NPN, as the vulnerability is only exploitable if NPN is enabled. If the target appears vulnerable, the script launches multiple concurrent exploit attempts, each trying to trigger the buffer overread and read leaked memory data from the server. All network interactions are logged, and any potentially leaked data is reported. The README provides a brief description and a link to the CVE entry. The exploit is untested and theoretical, as noted in the comments, but it demonstrates the attack logic based on public information. No hardcoded endpoints are present; the user supplies the target at runtime.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A buffer-overread vulnerability in OpenSSL's SSL_select_next_proto handling.
An OpenSSL buffer-overread issue in SSL_select_next_proto that can disclose up to 255 bytes of process memory or cause a crash when an application calls the API with a zero-length client protocol list. Exploitation requires an application configuration or programming error and is described as unlikely to be attacker-controlled.
An OpenSSL buffer-overread vulnerability in SSL_select_next_proto affecting OpenSSL packages on Red Hat Enterprise Linux 6.
A critical, remotely exploitable vulnerability affecting the mingw-openssl package on TencentOS Server 3, with potential high-impact confidentiality and availability compromise.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.