https://seclists.org/oss-sec/2026/q2/270: [ADVISORY] curl: CVE-2026-7009: OCSP stapling bypass with Apple SecTrust
Published Apr 29, 2026
·Updated
Affected Software
2 affected components
curl curl>=8.17.0<=8.19.0
curl libcurl>=8.17.0<=8.19.0
Frequently Asked Questions
1
What is the severity of CVE-2026-7009?
CVE-2026-7009 is classified as a medium severity vulnerability.
2
How do I fix CVE-2026-7009?
To fix CVE-2026-7009, update to the latest version of curl that includes the security patch.
3
What does CVE-2026-7009 affect?
CVE-2026-7009 affects curl and libcurl when using the OCSP stapling feature with Apple SecTrust.
4
What are the potential consequences of CVE-2026-7009?
The potential consequences of CVE-2026-7009 include a bypass of the OCSP response check, which may lead to trusting invalid certificates.
5
When was CVE-2026-7009 published?
CVE-2026-7009 was published on April 29, 2026.