PT-2026-99336 · Netty · Netty
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Netty versions 4.2.11.Final through 4.2.17.Final
Description
An incomplete hostname verification fix exists in the QUIC certificate verification path when utilizing a plain
X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, which prevents endpoint identification from executing even if HTTPS verification is configured. This allows network attackers to present a certificate chain for an incorrect hostname that the plain trust manager accepts, effectively bypassing hostname authentication for QUIC clients.Recommendations
Update Netty to version 4.2.18.Final.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netty