Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-56820

около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 7.4
EPSS: Низкий
redhat логотип

CVE-2026-56820

около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2026-56820

около 2 месяцев назад

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2026-56820

около 2 месяцев назад

Netty is a network application framework for development of protocol s ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-272m-gcwp-mpwg

около 2 месяцев назад

Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks

CVSS3: 7.4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3482-1

около 1 месяца назад

Security update for netty, netty-tcnative

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-56820

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
redhat логотип
CVE-2026-56820

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-56820

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-56820

Netty is a network application framework for development of protocol s ...

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-272m-gcwp-mpwg

Netty: Missing CertificateID Validation in OCSP Response Allows Replay Attacks

CVSS3: 7.4
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3482-1

Security update for netty, netty-tcnative

около 1 месяца назад

Уязвимостей на страницу