Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-7009

Опубликовано: 13 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 5.3

Описание

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

РелизСтатусПримечание
devel

not-affected

apple only
esm-infra-legacy/trusty

not-affected

apple only
esm-infra-legacy/xenial

not-affected

apple only
esm-infra/bionic

not-affected

apple only
esm-infra/focal

not-affected

apple only
esm-infra/xenial

not-affected

apple only
jammy

not-affected

apple only
noble

not-affected

apple only
questing

not-affected

apple only
resolute

not-affected

apple only

Показывать по

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
nvd
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

CVSS3: 5.3
debian
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, ...

CVSS3: 5.3
github
3 месяца назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

5.3 Medium

CVSS3