Certificate Verification Flaw in MsQuic Implementation by Microsoft
CVE-2026-105794
What is CVE-2026-105794?
MsQuic, a cross-platform C implementation of the IETF QUIC protocol, faced a vulnerability pre-versions 2.4.20, 2.5.11, and 2.6.1. This issue arises when clients utilizing the OpenSSL or QuicTLS TLS backend fail to properly verify that the server certificate aligns with the intended target server hostname. An attacker positioned on the network could exploit this weakness by presenting a fraudulent certificate, enabling them to impersonate the server in a man-in-the-middle attack. The vulnerability does not affect the Schannel backend. Microsoft has addressed this issue in subsequent versions, ensuring enhanced security for MsQuic users.
Affected Version(s)
msquic < 2.4.20 < 2.4.20
msquic >= 2.5.0, < 2.5.11 < 2.5.0, 2.5.11
msquic >= 2.6.0, < 2.6.1 < 2.6.0, 2.6.1