Impact
The vulnerability is a missing Extended Key Usage (EKU) check in the Netty OCSP client. Because the client does not verify that the certificate presented for revocation contains the appropriate EKU, an attacker can supply or use a revoked certificate without detection. This flaw allows certificate revocation bypass, potentially enabling the use of compromised or revoked certificates to establish secure connections, undermining the integrity and authenticity guarantees of TLS. The weakness is classified as CWE‑1035, an improper check of a cryptographic parameter or property.
Affected Systems
Affected software is the Red Hat build of Apache Camel for Spring Boot 4, which bundles a Netty library that implements the OCSP client. The flaw exists in all releases of this product that include the vulnerable Netty version. If an installation has not applied the vendor patch, it is considered vulnerable until a fixed version is installed.
Risk and Exploitability
The CVSS base score is 5.9, indicating a moderate impact. The EPSS score is 0.00226, reflecting a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is application-level, where the affected application relies on Netty’s OCSP verification to enforce certificate revocation. An attacker would need sufficient influence over the certificate presented or the OCSP responder to induce a revoked certificate to be accepted. Because the vulnerability is limited to the OCSP client check, it does not provide direct code execution or privilege escalation, but it can undermine secure communications and facilitate man-in-the-middle attacks.
OpenCVE Enrichment