CVE-2026-7009
MEDIUMcurl 8.17.0-8.20.0 - Improper Certificate Validation via OCSP Stapling
Title source: llmDescription
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.
References (4)
Core 4
Core References
Scores
CVSS v3
5.3
EPSS
0.0001
EPSS Percentile
2.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-295
Status
published
Products (4)
curl/curl
8.17.0
curl/curl
8.18.0
curl/curl
8.19.0
haxx/curl
8.17.0 - 8.20.0
Published
May 13, 2026
Tracked Since
May 13, 2026