Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wrp-2fvc-9x8r

Опубликовано: 18 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.9

Описание

Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

EPSS

Процентиль: 14%
0.00226
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 дня назад

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.

CVSS3: 5.9
redhat
14 дней назад

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.

CVSS3: 5.9
nvd
6 дней назад

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.

CVSS3: 5.9
debian
6 дней назад

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) ...

EPSS

Процентиль: 14%
0.00226
Низкий

5.9 Medium

CVSS3