CVE-2026-56821: Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator
OcspServerCertificateValidator flags an out-of-date OCSP response but does not stop processing it, so an expired GOOD response is still reported as VALID, letting an on-path attacker replay a stale GOOD response to bypass revocation of a since-revoked certificate.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-56821 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →