GHSA-4qw4-fmqv-qhv8HighCVSS 7.5

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification...

Published
September 26, 2026
Last Modified
September 26, 2026

🔗 CVE IDs covered (1)

📋 Description

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.

🔗 References (6)