When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
References
| Link | Resource |
|---|---|
| https://curl.se/docs/CVE-2026-7009.html | Patch Vendor Advisory |
| https://curl.se/docs/CVE-2026-7009.json | Product |
| https://hackerone.com/reports/3694390 | Exploit Issue Tracking Patch |
| http://www.openwall.com/lists/oss-security/2026/04/29/12 | Mailing List Patch Third Party Advisory |
| https://hackerone.com/reports/3694390 | Exploit Issue Tracking Patch |
Configurations
History
No history.
Information
Published : 2026-05-13 13:01
Updated : 2026-06-17 11:01
NVD link : CVE-2026-7009
Mitre link : CVE-2026-7009
CVE.ORG link : CVE-2026-7009
JSON object : View
Products Affected
haxx
- curl
CWE
CWE-295
Improper Certificate Validation
