VYPR

netty-handler-ssl-ocsp

by Netty

Source repositories

CVEs (2)

  • CVE-2026-44249HigJun 11, 2026
    risk 0.46cvss 8.1epss 0.01

    Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid…

  • CVE-2026-93493MedSep 18, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission causes the OCSP validation to be silently…