Improper Check for Certificate Revocation in Netty - #VU148880

 

Improper Check for Certificate Revocation in Netty - #VU148880

Published: September 10, 2026


Vulnerability identifier: #VU148880
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-299
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certificate revocation validation.

The vulnerability exists due to an improper check for certificate revocation in OcspServerCertificateValidator when processing an OCSP response that omits the optional nextUpdate field. A remote attacker can supply a crafted OCSP response to bypass certificate revocation validation.

Nonce validation is disabled by default.


Affected software

Netty

Remediation

Install security update from vendor's website.

Netty - addressed in versions 4.1.138, 4.2.18

External References

Related Security Bulletins