Description
A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission causes the OCSP validation to be silently skipped, leading to applications proceeding with an unvalidated certificate. This can result in a bypass of security controls where certificate validation is expected.
Published: 2026-09-18
Score: n/a
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-jj3c-mwvr-9g52 for fixed versions and remediation guidance.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission causes the OCSP validation to be silently skipped, leading to applications proceeding with an unvalidated certificate. This can result in a bypass of security controls where certificate validation is expected.
Title Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: ocsp validation silently skipped when a response omits the optional nextupdate field
First Time appeared Redhat
Redhat camel Spring Boot
Weaknesses CWE-299
CPEs cpe:/a:redhat:camel_spring_boot:4
Vendors & Products Redhat
Redhat camel Spring Boot
References

Subscriptions

Redhat Camel Spring Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-18T08:01:28.214Z

Reserved: 2026-09-18T07:17:42.853Z

Link: CVE-2026-93493

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-18T08:17:02.523

Modified: 2026-09-18T08:17:02.523

Link: CVE-2026-93493

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses