CVE-2026-93578: Missing EKU Check in OCSP Client Allows Revocation Bypass
CVE-2026-93578 Published on September 18, 2026
Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass
Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass
Timeline
Reported to Red Hat.
Made public.
Weakness Type
OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities
Weaknesses in this category are related to the A9 category in the OWASP Top Ten 2017.
Products Associated with CVE-2026-93578
Want to know whenever a new CVE is published for Red Hat Camel Spring Boot? stack.watch will email you.