Description
A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-jhjp-5q4f-8wr2 for fixed versions and remediation guidance.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass
Title Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass
First Time appeared Redhat
Redhat camel Spring Boot
Weaknesses CWE-1035
CPEs cpe:/a:redhat:camel_spring_boot:4
Vendors & Products Redhat
Redhat camel Spring Boot
References

Subscriptions

Redhat Camel Spring Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-18T16:54:16.469Z

Reserved: 2026-09-18T10:34:48.070Z

Link: CVE-2026-93578

cve-icon Vulnrichment

Updated: 2026-09-18T14:41:39.111Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T11:17:22.170

Modified: 2026-09-18T19:06:08.407

Link: CVE-2026-93578

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T00:54:25Z

Links: CVE-2026-93578 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T23:45:15Z

Weaknesses