Curl Vulnerabilities in Apple SecTrust and AWS-LC Exploitation Risks

Curl Vulnerabilities in Apple SecTrust and AWS-LC Exploitation Risks

First seen 8 Sep 2026, 19:20 UTC Redpacketsecurity 45.6

Article Content

Browse articles
ThreatCluster

Two vulnerabilities affecting curl's certificate verification were disclosed on September 8, 2026. The first, related to CVE-2026-7009, allows a bypass of the `--cert-status` option when using AWS-LC with Apple SecTrust, potentially accepting unverified certificates. The second issue involves curl's fallback to Apple SecTrust ignoring a custom Certificate Revocation List (CRL), allowing revoked certificates to be accepted. Both vulnerabilities require specific configurations, including the use of Apple SecTrust and particular TLS libraries. The impact is particularly concerning for environments relying on private or enterprise certificate authorities. Curl has released fixes for both issues, but the potential for exploitation remains if configurations are not updated. The vulnerabilities were classified as informative rather than critical, but they still pose risks to security practices. Current status indicates that both vulnerabilities have been patched.

Key Points: • CVE-2026-7009 allows bypassing OCSP checks in specific configurations with AWS-LC. • Curl's fallback to Apple SecTrust can ignore custom CRLs, accepting revoked certificates. • Both vulnerabilities have been patched, but specific configurations still pose risks.

Ask AI about this cluster

Timeline

2026-05-13
CVE-2026-7009 published
CVE-2026-7009 disclosed, detailing a bypass in curl's certificate status checking with AWS-LC.
Redpacketsecurity
2026-09-08
Curl vulnerabilities disclosed
Two vulnerabilities affecting curl's certificate verification were reported, one involving AWS-LC and another with Apple SecTrust.
Redpacketsecurity
2026-09-08
Patches released for curl
Curl's security team released fixes for both vulnerabilities, addressing the bypass and CRL issues.
Redpacketsecurity