Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when… (CVE-2026-100665)
Netty versions from 4.2.11.Final up to but not including 4.2.18.Final have an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. This flaw allows attackers on the network path to bypass hostname authentication by presenting a certificate chain for a wrong hostname that the trust manager accepts.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-100665) affects Netty versions starting from 4.2.11.Final before 4.2.18.Final. The issue arises because the BoringSSLCertificateVerifyCallback discards the SSLEngine for plain X509TrustManagers, preventing endpoint identification from executing even when HTTPS verification is configured. As a result, hostname verification is incomplete in the QUIC certificate verification path, enabling attackers on the network path to present a certificate chain for a hostname that does not match the intended endpoint, bypassing hostname authentication for QUIC clients.
Potential Impact
An attacker positioned on the network path can present a certificate chain for a hostname different from the intended server. Due to the incomplete hostname verification, the client accepts this certificate, potentially allowing man-in-the-middle attacks or interception of QUIC traffic. The vulnerability impacts confidentiality but does not affect integrity or availability directly.
Mitigation Recommendations
No explicit patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider avoiding affected versions or implementing additional network-layer protections to mitigate the risk.
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when… (CVE-2026-100665)
Description
Netty versions from 4.2.11.Final up to but not including 4.2.18.Final have an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. This flaw allows attackers on the network path to bypass hostname authentication by presenting a certificate chain for a wrong hostname that the trust manager accepts.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-100665) affects Netty versions starting from 4.2.11.Final before 4.2.18.Final. The issue arises because the BoringSSLCertificateVerifyCallback discards the SSLEngine for plain X509TrustManagers, preventing endpoint identification from executing even when HTTPS verification is configured. As a result, hostname verification is incomplete in the QUIC certificate verification path, enabling attackers on the network path to present a certificate chain for a hostname that does not match the intended endpoint, bypassing hostname authentication for QUIC clients.
Potential Impact
An attacker positioned on the network path can present a certificate chain for a hostname different from the intended server. Due to the incomplete hostname verification, the client accepts this certificate, potentially allowing man-in-the-middle attacks or interception of QUIC traffic. The vulnerability impacts confidentiality but does not affect integrity or availability directly.
Mitigation Recommendations
No explicit patch or remediation details are provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should consider avoiding affected versions or implementing additional network-layer protections to mitigate the risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4qw4-fmqv-qhv8
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-100665"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
Threat ID: 6ab89be0f7a7c54106942056
Added to database: 09/27/2026, 04:30:24 UTC
Last enriched: 09/27/2026, 04:43:13 UTC
Last updated: 09/28/2026, 01:47:40 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.