Junglewise Threat Intelligence

CVE-2026-56822: Netty TOCTOU race condition in OcspServerCertificateValidator

CVE-2026-56822 · Severity: high · CVSS 7.4 · Published 2026-07-29

Technologies: Netty Project Netty Handler SSL OCSP. Vendors: Netty, Netty Project.

Executive brief

Netty is a widely used networking framework that helps Java applications communicate over the internet. A security flaw in its certificate validation component allows a client to mistakenly send sensitive data to a server even if that server's security certificate has been revoked. This occurs because the system signals a successful connection before finishing the background check on the certificate's validity, potentially exposing private information to untrusted or compromised servers.

Technical details

A time-of-check time-of-use (TOCTOU) vulnerability exists in Netty's OcspServerCertificateValidator. When an SslHandshakeCompletionEvent is received, the validator immediately triggers the event for downstream handlers before the asynchronous OCSP (Online Certificate Status Protocol) query initiated via OcspClient.query completes. This race condition allows downstream handlers to begin sending application data or processing server responses before the certificate's revocation status is confirmed. If the certificate is later found to be revoked, the channel is closed, but sensitive data may have already been leaked. The issue is fixed in versions 4.1.136.Final and 4.2.16.Final.

Affected products

  • Netty netty-handler-ssl-ocsp < 4.1.136.Final, >= 4.2.0.Final, < 4.2.16.Final

Timeline

  • 2026-07-14: advisory: GitHub Security Advisory published
  • 2026-07-28: disclosed: NVD publication date

References

Related threats