Threat Advisory

Netty Missing CertificateID Validation Allows Replay Attacks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in netty-handler-ssl-ocsp, a package used for handling SSL/TLS connections. The overall risk and impact of these vulnerabilities are significant, as they could allow attackers to exploit weaknesses in the OCSP response validation process. Affected version range is 4.2.16.final.

CVE-2026-56820 : Missing CertificateID validation in OCSP responses allows replay attacks on Netty connections. An attacker can exploit this vulnerability by sending a malicious OCSP response to the server, which will then accept it as valid.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in netty-handler-ssl-ocsp, a package used for handling SSL/TLS connections. The overall risk and impact of these vulnerabilities are significant, as they could allow attackers to exploit weaknesses in the OCSP response validation process. Affected version range is 4.2.16.final.

CVE-2026-56820 : Missing CertificateID validation in OCSP responses allows replay attacks on Netty connections. An attacker can exploit this vulnerability by sending a malicious OCSP response to the server, which will then accept it as valid.[emaillocker id="1283"]

CVE-2026-56821: Out-of-date OCSP responses are accepted by OcspServerCertificateValidator in Netty, allowing attackers to bypass validation checks and potentially gain unauthorized access. This vulnerability can be exploited by sending an outdated OCSP response to the server.

CVE-2026-56822: A time-of-check-to-time-of-use (TOCTOU) vulnerability exists in OcspServerCertificateValidator, allowing attackers to manipulate the OCSP response after it has been validated. This could potentially lead to unauthorized access or data tampering.

These vulnerabilities collectively present a significant risk to systems that rely on Netty for SSL/TLS connections. Administrators should review their exposure and apply updates as soon as possible.

RECOMMENDATION:

We recommend you refer this link: https://github.com/advisories/GHSA-272m-gcwp-mpwg

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu