Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v355-7mqg-qj9c

Опубликовано: 13 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

EPSS

Процентиль: 19%
0.00267
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
redhat
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
nvd
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
debian
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, ...

EPSS

Процентиль: 19%
0.00267
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295