Hostname Verification Bypass in Netty QUIC Product by Netty
CVE-2026-100665

8.7HIGH

Key Information:

Vendor

Netty

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100665?

Netty versions prior to 4.2.18.Final exhibit an incomplete fix for hostname verification in the QUIC certificate verification process when using a X509TrustManager. The implementation fails to adequately enforce endpoint identification due to the BoringSSLCertificateVerifyCallback disregarding the SSLEngine with plain trust managers. This oversight allows malicious actors on the network to present a fraudulent certificate chain that bypasses the expected hostname validation for QUIC clients, posing significant security risks.

Affected Version(s)

netty 4.2.11.Final < 4.2.18.Final

netty 4.2.18.Final

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rexpository
.