Netty netty-handler-ssl-ocsp: OCSP nextUpdate Missing Skip Validation
CVE-2026-93493 Published on September 18, 2026

Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: ocsp validation silently skipped when a response omits the optional nextupdate field
A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission causes the OCSP validation to be silently skipped, leading to applications proceeding with an unvalidated certificate. This can result in a bypass of security controls where certificate validation is expected.

NVD

Timeline

Reported to Red Hat.

Made public.

Weakness Type

Improper Check for Certificate Revocation

The software does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised. An improper check for certificate revocation is a far more serious flaw than related certificate failures. This is because the use of any revoked certificate is almost certainly malicious. The most common reason for certificate revocation is compromise of the system in question, with the result that no legitimate servers will be using a revoked certificate, unless they are sorely out of sync.


Products Associated with CVE-2026-93493

Want to know whenever a new CVE is published for Red Hat Camel Spring Boot? stack.watch will email you.

 

Affected Versions

Red Hat build of Apache Camel for Spring Boot 4: