


Perceptive Security
SOC/SIEM Consultancy

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwa…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 01:00:51
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies, Supply Chain & Dependencies
A vulnerability in the Netty network application framework allows sensitive data to be sent to servers with revoked TLS certificates due to a race condition in OCSP validation. The OcspServerCertificateValidator prematurely forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes, causing downstream handlers to believe the TLS handshake succeeded. This allows clients to transmit sensitive application data such as HTTP requests to a revoked server before the channel is eventually closed. The flaw exists in io.netty.handler.ssl.ocsp.OcspServerCertificateValidator where the handshake event is fired immediately while the OCSP query runs asynchronously. Affected versions are prior to 4.1.136.Final and 4.2.16.Final. The issue has been patched in Netty versions 4.1.136.Final and 4.2.16.Final. Organizations using Netty with OCSP certificate validation should upgrade immediately to mitigate the risk of data leakage to compromised or malicious servers.
Technical details
Mitigation steps:
Affected products:
Netty < 4.1.136.Final
Netty < 4.2.16.Final
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-56822
https://github.com/netty/netty/security/advisories/GHSA-wc96-39fc-566f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
