THREAT OPS › Threat News › [NVD] CVE-2026-56821 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, l
[NVD] CVE-2026-56821 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, l
CVE-2026-56821 CVSS: 7.4 HIGH Published: 2026-07-29T00:16:38.573
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD respons
Indicators of compromise
- CVE-2026-56821cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-56821