Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-56821

Опубликовано: 30 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.4

Описание

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

РелизСтатусПримечание
devel

needs-triage

esm-apps-legacy/xenial

needs-triage

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

esm-infra-legacy/trusty

needs-triage

jammy

needs-triage

noble

needs-triage

Показывать по

EPSS

Процентиль: 4%
0.0014
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 5.7
redhat
26 дней назад

A flaw was found in netty-handler-ssl-ocsp, a component of the Netty network application framework. The Online Certificate Status Protocol (OCSP) stapling validator in this component does not properly check certificate revocation status. This can allow an attacker to use revoked certificates without detection, potentially compromising secure communications.

CVSS3: 7.4
nvd
6 дней назад

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 7.4
debian
6 дней назад

Netty is an asynchronous, event-driven network application framework. ...

CVSS3: 7.4
github
12 дней назад

Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator

EPSS

Процентиль: 4%
0.0014
Низкий

7.4 High

CVSS3