Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-7009

Опубликовано: 13 мая 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Версия от 8.17.0 (включая) до 8.20.0 (исключая)

EPSS

Процентиль: 18%
0.00267
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
redhat
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
debian
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, ...

CVSS3: 5.3
github
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

EPSS

Процентиль: 18%
0.00267
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-295