Hostname Verification Bypass in Netty QUIC Product by Netty
CVE-2026-100665
8.7HIGH
What is CVE-2026-100665?
Netty versions prior to 4.2.18.Final exhibit an incomplete fix for hostname verification in the QUIC certificate verification process when using a X509TrustManager. The implementation fails to adequately enforce endpoint identification due to the BoringSSLCertificateVerifyCallback disregarding the SSLEngine with plain trust managers. This oversight allows malicious actors on the network to present a fraudulent certificate chain that bypasses the expected hostname validation for QUIC clients, posing significant security risks.
Affected Version(s)
netty 4.2.11.Final < 4.2.18.Final
netty 4.2.18.Final
