When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
References
| Link | Resource |
|---|---|
| https://curl.se/docs/CVE-2026-7009.html | Patch Vendor Advisory |
| https://curl.se/docs/CVE-2026-7009.json | Product |
| https://hackerone.com/reports/3694390 | Exploit Issue Tracking Patch |
| http://www.openwall.com/lists/oss-security/2026/04/29/12 | Mailing List Patch Third Party Advisory |
| https://hackerone.com/reports/3694390 | Exploit Issue Tracking Patch |
Configurations
History
14 May 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | |
| CWE | CWE-295 | |
| References | () https://curl.se/docs/CVE-2026-7009.html - Patch, Vendor Advisory | |
| References | () https://curl.se/docs/CVE-2026-7009.json - Product | |
| References | () https://hackerone.com/reports/3694390 - Exploit, Issue Tracking, Patch | |
| References | () http://www.openwall.com/lists/oss-security/2026/04/29/12 - Mailing List, Patch, Third Party Advisory | |
| First Time |
Haxx
Haxx curl |
13 May 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-13 13:01
Updated : 2026-05-14 14:17
NVD link : CVE-2026-7009
Mitre link : CVE-2026-7009
CVE.ORG link : CVE-2026-7009
JSON object : View
Products Affected
haxx
- curl
CWE
CWE-295
Improper Certificate Validation
