CVE-2026-56820
Netty OcspClient Bypass Revocation Checks Vulnerability
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability in Netty's `OcspClient` could allow a replay attack, bypassing certificate revocation checks. This occurs when a signed OCSP response for an unrelated certificate is accepted as valid for a different certificate, potentially allowing the use of revoked certificates. Uncertainty exists regarding the spec