netty-handler-ssl-ocsp vulnerabilities
CVEs whose affected-version data names the netty-handler-ssl-ocsp package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-93578Medium· 5.9PoCA flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client
A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate is…
▾ TwilightRed Hat · netty-handler-ssl-ocspEPSS 0.23%via NVD
CVE-2026-93493Medium· 5.9A flaw was found in Netty's `netty-handler-ssl-ocsp` component
A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission…
▾ SunlitRed Hat · netty-handler-ssl-ocspEPSS 0.22%via NVD