Skip to content
red-hatCVE-2026-93493

A flaw was found in Netty's `netty-handler-ssl-ocsp` component.

Medium5.9CVE-2026-93493 · Published Sep 18, 2026

Source advisory

Affected versions

PackageAffectedFixed in
Red Hat build of Apache Camel for Spring Boot 4
Vendor
all versionsNo fix yet
Details and references

A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission causes the OCSP validation to be silently skipped, leading to applications proceeding with an unvalidated certificate. This can result in a bypass of security controls where certificate validation is expected.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
no source yet
Weakness
CWE-299

More red-hat advisories

All
DateAdvisory
Sep 17A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker...
CVE-2026-90997High7.4fixed in Keycloak 26.7.4
Sep 17A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing.
CVE-2026-76781Medium5.5no fix yet
Sep 18A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with...
CVE-2026-89058High7.4fixed in Red Hat, Inc.: CVE records (CNA) 6.2.19.Final, Red Hat, Inc.: CVE records (CNA) 7.0.5.Final
Sep 18A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count.
CVE-2026-89059High7.5fixed in Red Hat, Inc.: CVE records (CNA) 6.2.19.Final, Red Hat, Inc.: CVE records (CNA) 7.0.5.Final
Sep 18A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte.
CVE-2026-93494High7.5no fix yet
Sep 17A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application...
CVE-2026-87742High7.5no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.