CVE-2026-7009
published 2026-05-13CVE-2026-7009: When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it…
PriorityP427medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.27%
18.6th percentile
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| curl | curl | 8.17.0 – 8.17.0 | — |
| curl | curl | 8.18.0 – 8.18.0 | — |
| curl | curl | 8.19.0 – 8.19.0 | — |
| haxx | curl | — | — |
| haxx | curl | >= 8.17.0 < 8.20.0 | 8.20.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v355-7mqg-qj9c: When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
ghsa_unreviewed·2026-05-13
CVE-2026-7009 [MEDIUM] CWE-295 GHSA-v355-7mqg-qj9c: When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
VulDB
cURL up to 8.19.0 OCSP Stapling certificate validation (51905671e07f087e28e57 / Nessus ID 311424)
vuldb·2026-05-01
CVE-2026-7009 [LOW] cURL up to 8.19.0 OCSP Stapling certificate validation (51905671e07f087e28e57 / Nessus ID 311424)
A vulnerability was found in cURL up to 8.19.0. It has been classified as critical. This vulnerability affects unknown code of the component OCSP Stapling Handler. Performing a manipulation results in improper certificate validation.
This vulnerability is cataloged as CVE-2026-7009. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
Red Hat
curl: Curl: Certificate validation bypass due to OCSP stapling flaw
vendor_redhat·2026-05-13·CVSS 5.3
CVE-2026-7009 [MEDIUM] CWE-295 curl: Curl: Certificate validation bypass due to OCSP stapling flaw
curl: Curl: Certificate validation bypass due to OCSP stapling flaw
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
A flaw was found in curl. When curl is configured to use the Certificate Status Request TLS (Transport Layer Security) extension, also known as OCSP (Online Certificate Status Protocol) stapling, it fails to properly detect issues with the OCSP response. This can lead curl to incorrectly validate a server certificate as legitimate, potentially allowing an attacker to bypass certificate validation and establish a connection to a malicious server.
Statement: This vulnerability affects
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
bugzilla·2026-06-22·CVSS 5.3
CVE-2026-7009 [MEDIUM] CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7009 mingw-curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
bugzilla·2026-06-22·CVSS 5.3
CVE-2026-7009 [MEDIUM] CVE-2026-7009 mingw-curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
CVE-2026-7009 mingw-curl: Curl: Certificate validation bypass due to OCSP stapling flaw [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw
bugzilla·2026-05-13·CVSS 5.3
CVE-2026-7009 [MEDIUM] CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw
CVE-2026-7009 curl: Curl: Certificate validation bypass due to OCSP stapling flaw
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
2026-05-13
Published