Impact
The vulnerability allows an attacker to supply a forged OCSP response that omits the optional nextUpdate field, causing the Netty component to silently skip validation. The resulting lack of certificate verification can enable the use of revoked or otherwise untrusted certificates, effectively bypassing application‑level security controls.
Affected Systems
The flaw affects Red Hat’s build of Apache Camel for Spring Boot 4, found in the Netty network library bundled with that product. The affected version range is reflected in the CPE string and corresponds to Camel 4 releases shipped by Red Hat.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, while the EPSS score of less than 1% shows a very low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation would require an attacker to reach the application over a network and supply a custom OCSP response; no exploitation preconditions beyond this are documented. In the absence of an official fix, monitoring for malformed OCSP traffic is recommended.
OpenCVE Enrichment