CVE-2026-7009
EUVD-2026-2993113.05.2026, 13:01
When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| haxx | curl | 8.17.0 ≤ 𝑥 < 8.20.0 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| curl | curl | 𝑥 ≤ 8.19.0 | CNA |
| curl | curl | 𝑥 ≤ 8.18.0 | CNA |
| curl | curl | 𝑥 ≤ 8.17.0 | CNA |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration