Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7009

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 5.3

Описание

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

A flaw was found in curl. When curl is configured to use the Certificate Status Request TLS (Transport Layer Security) extension, also known as OCSP (Online Certificate Status Protocol) stapling, it fails to properly detect issues with the OCSP response. This can lead curl to incorrectly validate a server certificate as legitimate, potentially allowing an attacker to bypass certificate validation and establish a connection to a malicious server.

Отчет

This vulnerability affects curl and libcurl certificate validation functionality. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability. The flaw was introduced in curl 8.17.0 as part of functionality that added support for certificate validation using Apple SecTrust together with OpenSSL-based TLS backends. The issue is particularly relevant for users who explicitly enable OCSP validation through --cert-status or CURLOPT_SSL_VERIFYSTATUS, as these options are intended to ensure that certificate revocation status is verified before a connection is accepted.

Red Hat products are not affected by this vulnerability. The vulnerable functionality was introduced in curl 8.17.0, while Red Hat products currently ship curl versions older than 8.17.0 and therefore do not contain the affected code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10curlNot affected
Red Hat Enterprise Linux 6curlNot affected
Red Hat Enterprise Linux 7curlNot affected
Red Hat Enterprise Linux 8curlNot affected
Red Hat Enterprise Linux 9curlNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat OpenShift Dev Spacesdevspaces/code-rhel9Not affected
Red Hat Trusted Profile Analyzerrhtpa/rhtpa-trustification-service-rhel9Not affected
Red Hat Hardened Imagescurl-main-8.20.0-2.hum1FixedRHSA-2026:1910619.05.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2476978curl: Curl: Certificate validation bypass due to OCSP stapling flaw

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
nvd
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
debian
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, ...

CVSS3: 5.3
github
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

5.3 Medium

CVSS3

Уязвимость CVE-2026-7009