« List of all CVEs

CVE-2020-8286

Published: 12/14/2020 Last updated: 11/15/2024 Reserved: 1/28/2020

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

CNA assigner: hackerone (36234546-b8fa-4601-9d6f-f4e334aa8ea1) Requested by: n/a

Opam packages affected (3)

conf-libcurl conf-mingw-w64-curl-i686 conf-mingw-w64-curl-x86_64

Products affected (1)

Product Vendor Version
https://github.com/curl/curl n/a < 10.0.20348.887

References (38)