CVE-2024-2466 — libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when — CVE Database · The Intelligence Room