Improper Certificate Validation Affecting libcurl package, versions [,8.20.0)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-CONAN-LIBCURL-16699584
  • published15 May 2026
  • disclosed13 May 2026
  • creditCarlos Carrillo

Introduced: 13 May 2026

NewCVE-2026-7009  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade libcurl to version 8.20.0 or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation in the OCSP stapling process with Apple SecTrust. An attacker can cause the client to accept invalid or revoked server certificates by exploiting the failure to properly detect OCSP response problems.

Note:

This is only exploitable if the following conditions are met:

  • The attacker possesses a compromised but legally structured certificate that has been revoked.

  • The attacker is in a Man-in-the-Middle (MitM) position to intercept the victim's traffic, or they must trick the victim application into connecting directly to an attacker-controlled server.

  • The victim application uses libcurl explicitly configured to request OCSP stapling (the Certificate Status Request TLS extension), which the maintainer notes is not a widely used feature and is not on by default.

  • The victim application must be running on an Apple OS, utilizing the Apple SecTrust native certificate store, but built with an OpenSSL-based backend.

CVSS Base Scores

version 4.0
version 3.1