- Description
- Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
- Source
- security-advisories@github.com
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 7.4
- Impact score
- 5.2
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
- security-advisories@github.com
- CWE-299
- Hype score
- Not currently trending
csirt_it: ‼ #Netty: disponibili #PoC per lo sfruttamento delle CVE-2026-56822 e CVE-2026-56821 Rischio: 🔴 Tipologia: 🔸 Security Feature Bypass 🔗 https://t.co/WhO2dztRjR ⚠ Importante mantenere aggiornati i sistemi https://t.co/KinTpVuDUm
@Vulcanux_
29 Jul 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
‼ #Netty: disponibili #PoC per lo sfruttamento delle CVE-2026-56822 e CVE-2026-56821 Rischio: 🔴 Tipologia: 🔸 Security Feature Bypass 🔗 https://t.co/sLaOxRZCO5 ⚠ Importante mantenere aggiornati i sistemi https://t.co/qz2V4ftYug
@csirt_it
29 Jul 2026
305 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-56821 Netty is an asynchronous, event-driven network application framework. Prior to versions https://t.co/fwsF510zXv and https://t.co/3EGrjSeLGf, the OcspServerCertificateValidator flags an ou… https://t.co/R2azRX20jZ ----- Traducció… https://t.co/utmtNg
@infoflowcloud
29 Jul 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes