Redpacketsecurity
Curl Vulnerabilities in Apple SecTrust and AWS-LC Exploitation Risks
Article Content
Two vulnerabilities affecting curl's certificate verification were disclosed on September 8, 2026. The first, related to CVE-2026-7009, allows a bypass of the `--cert-status` option when using AWS-LC with Apple SecTrust, potentially accepting unverified certificates. The second issue involves curl's fallback to Apple SecTrust ignoring a custom Certificate Revocation List (CRL), allowing revoked certificates to be accepted. Both vulnerabilities require specific configurations, including the use of Apple SecTrust and particular TLS libraries. The impact is particularly concerning for environments relying on private or enterprise certificate authorities. Curl has released fixes for both issues, but the potential for exploitation remains if configurations are not updated. The vulnerabilities were classified as informative rather than critical, but they still pose risks to security practices. Current status indicates that both vulnerabilities have been patched.
Key Points: • CVE-2026-7009 allows bypassing OCSP checks in specific configurations with AWS-LC. • Curl's fallback to Apple SecTrust can ignore custom CRLs, accepting revoked certificates. • Both vulnerabilities have been patched, but specific configurations still pose risks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.