What is CVE-2026-56820?
In Netty framework, the `OcspClient` fails to validate that the `CertificateID` in an OCSP response matches the requested one, allowing response replay attacks. This vulnerability affects versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final. Users should upgrade to the patched versions.
Azərbaycanca: Netty framework-də `OcspClient` komponenti OCSP cavabında `CertificateID` yoxlamasını düzgün aparmadığı üçün cavabı başqa sertifikatla əvəz etmək (replay) mümkündür. Bu zəiflik 4.2.0.Final - 4.2.15.Final və 4.1.135.Final-dən əvvəlki versiyalara təsir edir. İstifadəçilərə patched versiyalara yeniləmə tövsiyə olunur.
FAQ2
Which component in Netty is affected by CVE-2026-56820 and how is it exploited?
The vulnerability is in the `OcspClient` component. It fails to validate that the `CertificateID` in an OCSP response matches the requested one, allowing a replay attack with a different certificate.
Which Netty versions are affected by CVE-2026-56820?
Netty versions 4.2.0.Final through 4.2.15.Final and versions prior to 4.1.135.Final are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.