THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-56822 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstre

[NVD] CVE-2026-56822 (HIGH 7.4) — Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstre

mednvdPublished 2026-07-29

CVE-2026-56822 CVSS: 7.4 HIGH Published: 2026-07-29T00:16:38.717

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateValidator forwards the SslHandshakeCompletionEvent before the asynchronous OCSP validation completes. This allows the client's downstream handlers to send sensitive application data (e.g.,

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-56822