Vulnerability Details CVE-2026-7009
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify that the server certificate is
valid, it fails to detect OCSP problems and instead wrongly consider the
response as fine.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 2.0%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2026-7009
-
cpe:2.3:a:haxx:curl:8.17.0
-
cpe:2.3:a:haxx:curl:8.18.0