TLS Hostname Verification Bypass in Netty by Lightbend
CVE-2026-62243
8.7HIGH
What is CVE-2026-62243?
In certain versions of Netty, a vulnerability exists that disables TLS hostname verification when a plain X509TrustManager is utilized alongside the OpenSSL client path. This flaw can potentially allow a man-in-the-middle attacker to exploit it, presenting a forged certificate without being validated against the intended hostname. It affects Netty versions ranging from 4.2.0.Final to 4.2.16.Final and 4.1.0.Final to 4.1.136.Final. The issue has been resolved in subsequent releases 4.2.17.Final and 4.1.137.Final.
Affected Version(s)
netty 4.2.0.Final < 4.2.16.Final
netty 0 < 4.1.137.Final
netty 4.2.16.Final
