


Perceptive Security
SOC/SIEM Consultancy

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags…
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 01:00:51
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies, Supply Chain & Dependencies
A security vulnerability in the Netty network application framework allows an on-path attacker to bypass certificate revocation checks. The OcspServerCertificateValidator component fails to reject expired OCSP responses, reporting them as VALID even when they are out-of-date. This enables an attacker to replay a stale GOOD OCSP response to bypass revocation of a since-revoked certificate. Any application using the OcspServerCertificateValidator is affected, meaning revoked certificates can be accepted as valid. The vulnerability affects Netty versions prior to 4.1.136.Final and 4.2.16.Final. Fixes have been released in versions 4.1.136.Final and 4.2.16.Final. This is a medium-to-high severity issue as it undermines PKI trust mechanisms and certificate lifecycle management.
Technical details
Mitigation steps:
Affected products:
Netty 4.1.x prior to 4.1.136.Final
Netty 4.2.x prior to 4.2.16.Final
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-56821
https://github.com/netty/netty/security/advisories/GHSA-g7hg-vrcf-mvmr
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
