CVE-2026-56821
CVE-2026-56821 is a high-severity vulnerability in Netty with a CVSS 3.x base score of 7.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-299.
Key facts
- Severity: High (CVSS 3.x base score 7.4)
- EPSS exploit prediction: 0% (4th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-299
- Affected product: Netty
- Published:
- Last modified:
Description
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
Frequently asked questions
- What is CVE-2026-56821?
- Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate. Exploitation can lead to certificate revocation bypass via replay of an expired OCSP response. Any application using OcspServerCertificateValidator is affected; a revoked certificate can be accepted. This issue has been fixed in versions 4.1.136.Final and 4.2.16.Final.
- How severe is CVE-2026-56821?
- CVE-2026-56821 has a CVSS 3.x base score of 7.4, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-56821 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (4th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-56821?
- CVE-2026-56821 affects Netty. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-56821?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-56821 published?
- CVE-2026-56821 was published on 2026-07-29 and last updated on 2026-08-07.
References
Affected products (1)
- cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:*
More vulnerabilities in Netty
- CVE-2026-56817 — Critical (CVSS 9.8): Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final…
- CVE-2019-20445 — Critical (CVSS 9.1): HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second…
- CVE-2019-20444 — Critical (CVSS 9.1): HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a…
- CVE-2026-47691 — High (CVSS 8.7): Netty is a network application framework for development of protocol servers and clients. Prior to versions…
- CVE-2026-45674 — High (CVSS 8.7): Netty is a network application framework for development of protocol servers and clients. Prior to versions…
- CVE-2026-44249 — High (CVSS 8.1): Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to…
Other CWE-299 vulnerabilities
- CVE-2026-9636 — High (CVSS 8.2): A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP…
- CVE-2025-11955 — High (CVSS 8.2): Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2…
- CVE-2025-3085 — High (CVSS 8.1): A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails…
- CVE-2026-4428 — High (CVSS 7.4): A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly…
- CVE-2020-16228 — Medium (CVSS 6.4): In Patient Information Center iX (PICiX) Versions C.02 and C.03, PerformanceBridge Focal Point Version A.01,…
- CVE-2026-6899 — Medium (CVSS 5.6): Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in…