๐Ÿ” CVE Alert

CVE-2026-100665

HIGH 7.5

Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.

CWE CWE-295
Vendor netty
Product netty
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for netty netty

Be the first to know when new high vulnerabilities affecting netty netty are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

netty / netty
4.2.11.Final < 4.2.18.Final

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/netty/netty/security/advisories/GHSA-mj35-3qqm-q387 github.com: https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe github.com: https://github.com/netty/netty/commit/994e887ed9 vulncheck.com: https://www.vulncheck.com/advisories/netty-4.2.11-through-4.2.17-quic-hostname-verification-bypass

Credits

๐Ÿ” rexpository