CVE-2026-7009
When curl is told to use the Certificate Status Request TLS extension, often
referred to as *OCSP stapling*, to verify t
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.
MEDIUM · CVSS 5.3
EPSS 0.00013
Schedule remediation
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
Sigma rules7
YARA rules0