CVE-2026-56820Netty · Netty
Vulnerability data via NVD (ingested)
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`, which can lead to replay attack. `OcspClient.validateResponse` accepts a legitimately signed `GOOD` status response for an unrelated certificate issued by the same CA, allowing bypass of revocation checks for another certificate. This issue is fixed in versions 4.1.136.Final and 4.2.16.Final.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-56820product:"Netty Netty"http.html:"Netty"More intel sources (5)
vuln:CVE-2026-56820vulnerabilities.cve_id: CVE-2026-56820CVE-2026-56820CVE-2026-56820"CVE-2026-56820" exploit -site:nvd.nist.gov