Description
A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.
Published: 2026-09-18
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Certificate revocation bypass through missing EKU check in OCSP client
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing Extended Key Usage (EKU) check in the Netty OCSP client. Because the client does not verify that the certificate presented for revocation contains the appropriate EKU, an attacker can supply or use a revoked certificate without detection. This flaw allows certificate revocation bypass, potentially enabling the use of compromised or revoked certificates to establish secure connections, undermining the integrity and authenticity guarantees of TLS. The weakness is classified as CWE‑1035, an improper check of a cryptographic parameter or property.

Affected Systems

Affected software is the Red Hat build of Apache Camel for Spring Boot 4, which bundles a Netty library that implements the OCSP client. The flaw exists in all releases of this product that include the vulnerable Netty version. If an installation has not applied the vendor patch, it is considered vulnerable until a fixed version is installed.

Risk and Exploitability

The CVSS base score is 5.9, indicating a moderate impact. The EPSS score is 0.00226, reflecting a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is application-level, where the affected application relies on Netty’s OCSP verification to enforce certificate revocation. An attacker would need sufficient influence over the certificate presented or the OCSP responder to induce a revoked certificate to be accepted. Because the vulnerability is limited to the OCSP client check, it does not provide direct code execution or privilege escalation, but it can undermine secure communications and facilitate man-in-the-middle attacks.

Generated by OpenCVE AI on September 19, 2026 at 18:12 UTC.

Remediation

Vendor Workaround

See https://github.com/netty/netty/security/advisories/GHSA-jhjp-5q4f-8wr2 for fixed versions and remediation guidance.


OpenCVE Recommended Actions

  • Update the Netty library to a version that includes the EKU check, following the Red Hat advisory for patched releases.
  • Upgrade the Red Hat build of Apache Camel for Spring Boot 4 to the latest patched release that bundles the updated Netty library.
  • If immediate upgrade is not possible, apply the workaround recommended in the GitHub advisory, which includes using a patched netty-handler-ssl-ocsp module or implementing explicit EKU checks in application code.

Generated by OpenCVE AI on September 19, 2026 at 18:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot
Vendors & Products Io.netty
Io.netty netty-codec-http
Redhat build Of Apache Camel For Spring Boot

Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA), can exploit this by forging 'GOOD' OCSP responses for revoked certificates. This bypasses certificate revocation checks, allowing applications using Netty's OCSP Client to accept certificates that should have been revoked, leading to an authorization bypass.
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Title Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass Io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Fri, 18 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Missing Extended Key Usage (EKU) check in OCSP Client allows certificate revocation bypass
Title Netty: netty-handler-ssl-ocsp: io.netty/netty-handler-ssl-ocsp: netty: missing extended key usage (eku) check in ocsp client allows certificate revocation bypass
First Time appeared Redhat
Redhat camel Spring Boot
Weaknesses CWE-1035
CPEs cpe:/a:redhat:camel_spring_boot:4
Vendors & Products Redhat
Redhat camel Spring Boot
References

Subscriptions

Io.netty Netty-codec-http
Redhat Build Of Apache Camel For Spring Boot Camel Spring Boot
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-18T16:54:16.469Z

Reserved: 2026-09-18T10:34:48.070Z

Link: CVE-2026-93578

cve-icon Vulnrichment

Updated: 2026-09-18T14:41:39.111Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T11:17:22.170

Modified: 2026-09-18T19:06:08.407

Link: CVE-2026-93578

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T00:54:25Z

Links: CVE-2026-93578 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:25:50Z

Weaknesses