io.netty:netty-handler-ssl-ocsp vulnerabilities
CVEs whose affected-version data names the io.netty:netty-handler-ssl-ocsp package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-56821High· 7.4Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
▾ Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.22%via GHSA
CVE-2026-56822High· 7.4Netty: TOCTOU in OcspServerCertificateValidator
Netty: TOCTOU in OcspServerCertificateValidator
▾ Twilightnetty · io.netty:netty-handler-ssl-ocspEPSS 0.17%via GHSA