Bug 2507477 (CVE-2026-56821)

Summary: CVE-2026-56821 io.netty/netty-handler-ssl-ocsp: Netty: Improper certificate revocation check in netty-handler-ssl-ocsp
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: anujha, asoldano, bbaranow, bmaxwell, bstansbe, dlofthou, fmariani, gmalinko, istudens, ivassile, iweiss, janstey, jwon, mcarlett, mosmerov, msvehla, nwallace, pberan, pesilva, pjindal, pmackay, rstancel, rstepani, tcunning, thjenkin, vdosoudi, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in netty-handler-ssl-ocsp, a component of the Netty network application framework. The Online Certificate Status Protocol (OCSP) stapling validator in this component does not properly check certificate revocation status. This can allow an attacker to use revoked certificates without detection, potentially compromising secure communications.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-07-27 14:37:12 UTC
Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final, the OCSP stapling validator in netty-handler-ssl-ocsp does not properly check certificate revocation status. The implementation may skip revocation checks under certain conditions or fail to properly parse OCSP responses indicating revoked certificates. An attacker can use revoked certificates without detection, potentially compromising secure communications. This issue is fixed in versions 4.1.136.Final and later.