Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-93578

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 5.9

Описание

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.

Отчет

This Moderate flaw in Netty's OcspClient allows a network-positioned attacker, possessing any valid certificate from the same Certificate Authority, to bypass certificate revocation checks by forging "GOOD" OCSP responses.

Меры по смягчению последствий

See https://github.com/netty/netty/security/advisories/GHSA-jhjp-5q4f-8wr2 for fixed versions and remediation guidance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 4netty-handler-ssl-ocspAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1035
https://bugzilla.redhat.com/show_bug.cgi?id=2536969io.netty/netty-handler-ssl-ocsp: Netty: Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
3 дня назад

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.

CVSS3: 5.9
nvd
6 дней назад

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.

CVSS3: 5.9
debian
6 дней назад

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) ...

CVSS3: 5.9
github
6 дней назад

Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

5.9 Medium

CVSS3