CVE-2026-7009

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.
References
Link Resource
https://curl.se/docs/CVE-2026-7009.html Patch Vendor Advisory
https://curl.se/docs/CVE-2026-7009.json Product
https://hackerone.com/reports/3694390 Exploit Issue Tracking Patch
http://www.openwall.com/lists/oss-security/2026/04/29/12 Mailing List Patch Third Party Advisory
https://hackerone.com/reports/3694390 Exploit Issue Tracking Patch
Configurations

Configuration 1 (hide)

cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*

History

14 May 2026, 14:17

Type Values Removed Values Added
CPE cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
CWE CWE-295
References () https://curl.se/docs/CVE-2026-7009.html - () https://curl.se/docs/CVE-2026-7009.html - Patch, Vendor Advisory
References () https://curl.se/docs/CVE-2026-7009.json - () https://curl.se/docs/CVE-2026-7009.json - Product
References () https://hackerone.com/reports/3694390 - () https://hackerone.com/reports/3694390 - Exploit, Issue Tracking, Patch
References () http://www.openwall.com/lists/oss-security/2026/04/29/12 - () http://www.openwall.com/lists/oss-security/2026/04/29/12 - Mailing List, Patch, Third Party Advisory
First Time Haxx
Haxx curl

13 May 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-13 13:01

Updated : 2026-05-14 14:17


NVD link : CVE-2026-7009

Mitre link : CVE-2026-7009

CVE.ORG link : CVE-2026-7009


JSON object : View

Products Affected

haxx

  • curl
CWE
CWE-295

Improper Certificate Validation