Skip to content
Red HatCVE-2026-93578

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client

Medium5.9CVE-2026-93578 · Published Sep 18, 2026

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat build of Apache Camel for Spring Boot 4
Product
all versionsNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1035

More Red Hat advisories

All Red Hat
Advisory
Red Hat OpenShift Container Platform 4: server-side request forgery
Critical9.3Sep 18
Red Hat Netty: request smuggling
Medium6.5Sep 18
Red Hat Netty: request smuggling
Medium6.5Sep 18
A flaw was found in cockpit-files
Medium6.1Sep 18
Red Hat cockpit-files. This vulnerability: race condition
Medium6.0Sep 18
Red Hat cockpit-files: race condition
Medium6.0Sep 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.