top of page
perceptive_background_267k.jpg

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags…

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 01:00:51

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Web Technologies, Supply Chain & Dependencies

A security vulnerability in the Netty network application framework allows an on-path attacker to bypass certificate revocation checks. The OcspServerCertificateValidator component fails to reject expired OCSP responses, reporting them as VALID even when they are out-of-date. This enables an attacker to replay a stale GOOD OCSP response to bypass revocation of a since-revoked certificate. Any application using the OcspServerCertificateValidator is affected, meaning revoked certificates can be accepted as valid. The vulnerability affects Netty versions prior to 4.1.136.Final and 4.2.16.Final. Fixes have been released in versions 4.1.136.Final and 4.2.16.Final. This is a medium-to-high severity issue as it undermines PKI trust mechanisms and certificate lifecycle management.

Technical details

Mitigation steps:

Affected products:

Netty 4.1.x prior to 4.1.136.Final
Netty 4.2.x prior to 4.2.16.Final

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page