What is CVE-2026-56821?
CVE-2026-56821 is a vulnerability in the Netty framework where the OcspServerCertificateValidator flags an out-of-date OCSP response but continues processing it, treating an expired GOOD response as VALID. This allows an on-path attacker to bypass certificate validation; upgrading to Netty 4.1.136.Final or 4.2.16.Final is recommended.
Azərbaycanca: CVE-2026-56821, Netty framework-də aşkarlanan zəiflikdir. Keçmiş OCSP cavabını 'etibarsız' işarələməsinə baxmayaraq, emalı dayandırmır və vaxtı keçmiş GOOD cavabı etibarlı kimi qəbul edir. Bu, yoldakı təcavüzkarın (on-path attacker) etibarsız sertifikatı qəbul etdirməsinə şərait yaradır; Netty 4.1.136.Final və 4.2.16.Final versiyalarına yeniləmə tövsiyə olunur.
FAQ2
What security issue does CVE-2026-56821 cause in the Netty framework?
The vulnerability causes the OcspServerCertificateValidator to flag an out-of-date OCSP response but continue processing it, treating an expired GOOD response as VALID. This allows an on-path attacker to bypass certificate validation by forcing the acceptance of an invalid certificate.
Which Netty versions should be upgraded to in order to mitigate CVE-2026-56821?
To mitigate this vulnerability, it is recommended to upgrade the Netty framework to versions 4.1.136.Final or 4.2.16.Final.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.