top of page
perceptive_background_267k.jpg

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwa…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 01:00:51

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Web Technologies, Supply Chain & Dependencies

A vulnerability in the Netty network application framework allows sensitive data to be sent to servers with revoked TLS certificates due to a race condition in OCSP validation. The OcspServerCertificateValidator prematurely forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes, causing downstream handlers to believe the TLS handshake succeeded. This allows clients to transmit sensitive application data such as HTTP requests to a revoked server before the channel is eventually closed. The flaw exists in io.netty.handler.ssl.ocsp.OcspServerCertificateValidator where the handshake event is fired immediately while the OCSP query runs asynchronously. Affected versions are prior to 4.1.136.Final and 4.2.16.Final. The issue has been patched in Netty versions 4.1.136.Final and 4.2.16.Final. Organizations using Netty with OCSP certificate validation should upgrade immediately to mitigate the risk of data leakage to compromised or malicious servers.

Technical details

Mitigation steps:

Affected products:

Netty < 4.1.136.Final
Netty < 4.2.16.Final

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page