Junglewise Threat Intelligence

CVE-2026-93578: Netty OCSP Client EKU verification bypass

CVE-2026-93578 · Severity: medium · CVSS 5.9 · Published 2026-09-18

Technologies: Netty. Vendors: Netty.

Executive brief

Netty is a popular Java networking library used in many enterprise applications. A flaw in its OCSP (certificate revocation checking) client allows attackers with a valid certificate from the same Certificate Authority to forge false "good" responses for revoked certificates, bypassing revocation checks and allowing applications to accept certificates that should have been rejected.

Technical details

The vulnerability is an authentication/authorization bypass caused by insufficient validation of OCSP responder certificates. Netty's OCSP Client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) extension on certificates presented by OCSP responders. An attacker holding any valid certificate issued by the same Certificate Authority can forge OCSP responses indicating revoked certificates are "GOOD", bypassing certificate revocation checks. This requires network access to intercept or control OCSP responses, but no specific authentication is required from the application. The impact is that applications relying on Netty's OCSP validation will incorrectly trust revoked certificates. No patch information is currently available.

Affected products

  • Netty Netty unknown

Timeline

  • 2026-09-18: disclosed

References

Related threats