PT-2020-6196 · Curl+9 · Curl+9

Published

2020-12-01

·

Updated

2026-05-18

·

CVE-2020-8286

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions curl versions 7.41.0 through 7.73.0
Description The issue is related to an improper check for certificate revocation due to insufficient verification of the OCSP response. This allows an attacker to provide a fraudulent OCSP response, potentially breaching a TLS server and affecting data integrity. The vulnerability is associated with errors in the certificate authentication procedure. The CURLOPT SSL VERIFYSTATUS option in libcurl, which offers OCSP stapling, and the --cert-status option using the curl tool, are related to this issue. The vulnerability could be exploited by an attacker to provide a fake OCSP response that appears legitimate.
Recommendations For curl versions 7.41.0 through 7.73.0, this issue was addressed with improved checks, implying that updating to a version with these improved checks would resolve the issue. As a temporary workaround, consider disabling the use of the CURLOPT SSL VERIFYSTATUS option or the --cert-status option until a patch is available. Restrict access to the TLS negotiation process to minimize the risk of exploitation. Avoid using the OCSP response verification feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability, other than that improved checks have been implemented to address the issue.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3572
ALT-PU-2020-3573
ALT-PU-2021-1592
BDU:2021-03510
CESA-2021_1610
CLEANSTART-2026-AY18527
CLEANSTART-2026-BW46578
CLEANSTART-2026-DI23929
CLEANSTART-2026-LQ42192
CLEANSTART-2026-OF85770
CVE-2020-8286
DLA-2500-1
DSA-4881-1
JLSEC-2025-25
MGASA-2020-0482
OESA-2021-1004
OPENSUSE-SU-2020:2238-1
OPENSUSE-SU-2020:2249-1
OPENSUSE-SU-2020_2238-1
OPENSUSE-SU-2020_2249-1
OPENSUSE-SU-2024:10582-1
RHSA-2021:1610
RHSA-2021:2472
RHSA-2021_1610
RLSA-2021:1610
SUSE-SU-2020:3733-1
SUSE-SU-2020:3735-1
SUSE-SU-2020:3739-1
SUSE-SU-2021:1786-1
USN-4665-1

Affected Products

Alt Linux
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Rocky Linux
Suse
Ubuntu
Curl