- Description
- Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- netty
CVSS 3.1
- Type
- Secondary
- Base score
- 7.4
- Impact score
- 5.2
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
- security-advisories@github.com
- CWE-299
- Hype score
- Not currently trending
csirt_it: ‼ #Netty: disponibili #PoC per lo sfruttamento delle CVE-2026-56822 e CVE-2026-56821 Rischio: 🔴 Tipologia: 🔸 Security Feature Bypass 🔗 https://t.co/WhO2dztRjR ⚠ Importante mantenere aggiornati i sistemi https://t.co/KinTpVuDUm
@Vulcanux_
29 Jul 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
‼ #Netty: disponibili #PoC per lo sfruttamento delle CVE-2026-56822 e CVE-2026-56821 Rischio: 🔴 Tipologia: 🔸 Security Feature Bypass 🔗 https://t.co/sLaOxRZCO5 ⚠ Importante mantenere aggiornati i sistemi https://t.co/qz2V4ftYug
@csirt_it
29 Jul 2026
311 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2026-56821 Netty is an asynchronous, event-driven network application framework. Prior to versions https://t.co/fwsF510zXv and https://t.co/3EGrjSeLGf, the OcspServerCertificateValidator flags an ou… https://t.co/R2azRX20jZ ----- Traducció… https://t.co/utmtNg
@infoflowcloud
29 Jul 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3A15093F-C6A7-4FCF-81BA-939CD522D1DD",
"versionEndExcluding": "4.1.136",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4DE4BC35-4405-49B5-A2A8-A700C7F63C8B",
"versionEndExcluding": "4.2.16",
"versionStartIncluding": "4.2.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]