CVE-2026-7009Patch(haxx / curl)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch haxx curl systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and instead wrongly consider the response as fine.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • curl

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-04-30); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
curl

Deep dive

Activity timeline10 mentions / 7d
01122Mentions · 2026-04-29: 1Mentions · 2026-04-30: 2Mentions · 2026-05-02: 1Mentions · 2026-05-11: 2Mentions · 2026-08-31: 2Mentions · 2026-09-01: 1Mentions · 2026-09-08: 1PoC Mentioned / Linked · 2026-05-02: 1PoC Mentioned / Linked · 2026-08-31: 1PoC Mentioned / Linked · 2026-09-01: 1Patch / Workaround · 2026-05-11: 2Patch / Workaround · 2026-08-31: 2Patch / Workaround · 2026-09-01: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-02: 1Technical Details · 2026-08-31: 2Technical Details · 2026-09-08: 104-2904-3005-0205-1108-3109-0109-08
Signal classification4 categories
Patch
660.0%
Disclosure
220.0%
General
110.0%
PoC
110.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-291
General1
2026-04-302
Disclosure2
2026-05-021
PoC1
2026-05-112
Patch2
2026-08-312
Patch2
2026-09-011
Patch1
2026-09-081
Patch1
Full discourse10 posts
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Patch

    🛡️ HackerOne Reports 06: Incomplete fix for CVE-2026-7009: GCC/SecTrust builds silently discard stapled OCSP responses: https://hackerone.com/reports/3973093 41: `main_checkfds()` pipe reuse leaks proxy credentials into HTTPS upload body: https://hackerone.com/reports/3973158 33: CONNECT_ONLY raw I/O selects wrong connection after CURLOPT_SHARE detach (incomplete fix for CVE-2020-8231): https://hackerone.com/reports/3971585 18: Explicit IPv6 proxy zone ID silently ignored proxy credentials sent to wrong interface: https://hackerone.com/reports/3973127

    Post summary

    The brief report points out incomplete fixes for a few CVEs and provides links to HackerOne, but it does not discuss PoCs, active exploitation, or detailed technical data.

    010431.5K
    40.5K followersView on X
  • 𝕏 Bug Bounty Writeups 𝕏@bountywriteups
    Patch

    🛡️ HackerOne Reports • 06: Incomplete fix for CVE-2026-7009: GCC/SecTrust builds silently discard stapled OCSP responses: https://hackerone.com/reports/3973093 • 41: `main_checkfds()` pipe reuse leaks proxy credentials into HTTPS upload body: https://hackerone.com/reports/3973158 • 33: CONNECT_ONLY raw I/O selects wrong connection after CURLOPT_SHARE detach (incomplete fix for CVE-2020-8231): https://hackerone.com/reports/3971585 • 18: Explicit IPv6 proxy zone ID silently ignored proxy credentials sent to wrong interface: https://hackerone.com/reports/3973127

    Post summary

    The brief report lists several HackerOne findings, noting technical details of each vulnerability and indicating that the existing vendor patches are incomplete.

    000421.5K
    40.5K followersView on X
  • ROHIT@rynosec
    Patch

    ⚡ 06: Incomplete fix for CVE-2026-7009: GCC/SecTrust builds silently discard stapled OCSP responses 👨🏻‍💻 giant_anteater ➟ curl ⬜ None 💰 None 🔗 https://hackerone.com/reports/3973093 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/tronoVlQLM

    Post summary

    The post highlights an incomplete vendor fix for CVE-2026-7009, noting that GCC/SecTrust builds silently discard stapled OCSP responses, and it references a HackerOne bug bounty report.

    00040395
    7.0K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl モジュール更新情報 8.20.0-1 https://kusanagi.tokyo/releases/24476/ KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 curl 8.20.0-1 この更新には脆弱性(CVE-2026-7168, CVE-2026-7009, CVE-2026-6429, CVE-2026-6276, CVE-2026-6253, CVE-2026-5773, CVE-2026-5545, CVE-2...

    Post summary

    The KUSANAGI release notes announce a module update that addresses multiple CVEs by deploying curl 8.20.0-1, indicating a patch release.

    0101085
    200 followersView on X
  • ROHIT@rynosec
    Patch

    ⚡ 08: CVE-2026-7009 fix incomplete for AWS-LC: `--cert-status` bypass on SecTrust path 👨🏻‍💻 giant_anteater ➟ curl ⬜ None 💰 None 🔗 https://hackerone.com/reports/3973111 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/0IzMUvMiRJ

    Post summary

    The tweet indicates that the fix for CVE-2026-7009 in AWS‑LC is incomplete, but no PoC, exploit, or active exploitation is discussed.

    00010271
    7.0K followersView on X
  • H1 Disclosed - Public Disclosures@h1Disclosed
    PoC

    ⚡ CVE-2026-7009: OCSP stapling bypass with Apple SecTrust 👨🏻‍💻 @3lcarry ➟ curl 🟧 Medium 💰 None 🔗 https://hackerone.com/reports/3694390 #bugbounty #bugbountytips #cybersecurity #infosec https://t.co/K5Abj1zLsf

    Post summary

    CVE‑2026‑7009 is an OCSP stapling bypass affecting Apple SecTrust, with a PoC linked via HackerOne that likely uses curl; no exploit code, patch, or active exploitation evidence is provided.

    00010346
    10.2K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    curl CVE-2026-6253: proxy credentials leak over redirect-to proxy CVE-2026-7009: OCSP stapling bypass with Apple SecTrust CVE-2026-6276: stale custom cookie host causes cookie leak CVE-2026-7168: cross-proxy Digest auth state leak 2/2

    Post summary

    The text lists four newly disclosed CVEs, each accompanied by a concise description of the vulnerability type (credential leak, OCSP stapling bypass, cookie leak, and digest auth state leak), but it provides no PoC, exploit code, active exploitation evidence, or patch information.

    00010211
    4.5K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-curl Module Update 8.20.0-1 https://kusanagi.tokyo/en/releases/24477/ KUSANAGI 9 modules have been updated. The updated modules are as follows: curl 8.20.0-1 This update includes support for vulnerability(CVE-2026-7168, CVE-2026-7009, CVE-2026-6429, CVE-2026-6276, CVE-2026-6253,...

    Post summary

    The statement announces a module update that patches a list of CVE vulnerabilities in kusanagi‑curl 8.20.0‑1, with no evidence of PoCs, exploitation, or false claims.

    0000040
    200 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    curlで8件の脆弱性 CVE-2026-7168 CVE-2026-7009 CVE-2026-6429 CVE-2026-6276 CVE-2026-6253 CVE-2026-5773 CVE-2026-5545 CVE-2026-4873 Published vulnerabilities for curl/libcurl https://curl.se/docs/security.html

    Post summary

    The text lists eight newly published CVEs for curl/libcurl and provides a link to the official security page for more information.

    00000396
    6.8K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7009 [ADVISORY] curl https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7009 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The text merely links to an advisory for CVE‑2026‑7009 without providing PoC, exploit details, active exploitation evidence, patches, or technical specifics.

    0000037
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphaxxcurl---

Explore more