Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
References
Configurations
Configuration 1 (hide)
|
History
30 Jul 2026, 14:48
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b - Patch | |
| References | () https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 - Patch | |
| References | () https://github.com/netty/netty/releases/tag/netty-4.1.136.Final - Release Notes | |
| References | () https://github.com/netty/netty/releases/tag/netty-4.2.16.Final - Release Notes | |
| References | () https://github.com/netty/netty/security/advisories/GHSA-272m-gcwp-mpwg - Exploit, Vendor Advisory | |
| First Time |
Netty netty
Netty |
|
| CPE | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* |
21 Jul 2026, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-21 23:17
Updated : 2026-07-30 14:48
NVD link : CVE-2026-56820
Mitre link : CVE-2026-56820
CVE.ORG link : CVE-2026-56820
JSON object : View
Products Affected
netty
- netty
CWE
CWE-295
Improper Certificate Validation
