CVE-2026-93578: Missing EKU Check in OCSP Client Allows Revocation Bypass
CVE-2026-93578 Published on September 18, 2026

Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass
Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass

NVD

Timeline

Reported to Red Hat.

Made public.

Weakness Type

OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities

Weaknesses in this category are related to the A9 category in the OWASP Top Ten 2017.


Products Associated with CVE-2026-93578

Want to know whenever a new CVE is published for Red Hat Camel Spring Boot? stack.watch will email you.

 

Affected Versions

Red Hat build of Apache Camel for Spring Boot 4: