PT-2026-99336 · Netty · Netty

·

CVE-2026-100665

·

Published

2026-09-26

·

Updated

2026-09-27

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Netty versions 4.2.11.Final through 4.2.17.Final
Description An incomplete hostname verification fix exists in the QUIC certificate verification path when utilizing a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, which prevents endpoint identification from executing even if HTTPS verification is configured. This allows network attackers to present a certificate chain for an incorrect hostname that the plain trust manager accepts, effectively bypassing hostname authentication for QUIC clients.
Recommendations Update Netty to version 4.2.18.Final.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100665
GHSA-MJ35-3QQM-Q387

Affected Products

Netty