Security Flaw in Netty's OCSP Handler Allows Certificate Bypass
CVE-2026-93493

Currently unrated

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 September 2026

What is CVE-2026-93493?

A flaw in Netty's netty-handler-ssl-ocsp component exposes applications to potential security risks by allowing a remote attacker to exploit the system. Specifically, when an Online Certificate Status Protocol (OCSP) response omits the optional nextUpdate field, the validation process is silently skipped. This allows applications to proceed with using an unvalidated certificate, undermining security controls that rely on proper certificate validation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.