Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients. | |
| Title | Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass | |
| First Time appeared |
Netty
Netty netty |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:2.3:a:netty:netty:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Netty
Netty netty |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T13:23:31.242Z
Reserved: 2026-09-26T02:33:59.039Z
Link: CVE-2026-100665
No data.
Status : Received
Published: 2026-09-26T14:16:49.677
Modified: 2026-09-26T14:16:49.677
Link: CVE-2026-100665
No data.
OpenCVE Enrichment
Updated: 2026-09-26T16:30:07Z
-
CWE-295
Improper Certificate Validation