THREAT OPS › Threat News › [NVD] CVE-2026-56822 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstre
[NVD] CVE-2026-56822 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstre
CVE-2026-56822 CVSS: 7.4 HIGH Published: 2026-07-29T00:16:38.717
Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send sensitive application data (e.g.,
Indicators of compromise
- CVE-2026-56822cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-56822