Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in netty-handler-ssl-ocsp, a component of the Netty network application framework. The Online Certificate Status Protocol (OCSP) stapling validator in this component does not properly check certificate revocation status. This can allow an attacker to use revoked certificates without detection, potentially compromising secure communications. | Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final. |
| Title | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp | Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator |
| Weaknesses | CWE-299 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 28 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in netty-handler-ssl-ocsp, a component of the Netty network application framework. The Online Certificate Status Protocol (OCSP) stapling validator in this component does not properly check certificate revocation status. This can allow an attacker to use revoked certificates without detection, potentially compromising secure communications. | |
| Title | io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp | |
| Weaknesses | CWE-93 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-28T23:07:13.616Z
Reserved: 2026-06-23T14:55:09.116Z
Link: CVE-2026-56821
No data.
No data.
OpenCVE Enrichment
No data.