GHSA-w5f4-fx9m-m4q7Critical
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
🔗 CVE IDs covered (1)
📋 Description
Summary
Improper TLS hostname verification allows a man-in-the-middle (MITM) attack on MsQuic.
Details
Only MsQuic with the OpenSSL and QuicTLS TLS backends is affected (the Schannel backend is not affected).
Patches
2.6.1, 2.5.11, and 2.4.20
Impact
An on-path attacker could spoof a server identity by using a certificate that doesn't match the intended target server hostname.
🎯 Affected products3
- nuget/Microsoft.Native.Quic.MsQuic.OpenSSL:< 2.4.20
- nuget/Microsoft.Native.Quic.MsQuic.OpenSSL:>= 2.5.0, < 2.5.11
- nuget/Microsoft.Native.Quic.MsQuic.OpenSSL:>= 2.6.0, < 2.6.1
🔗 References (14)
- https://github.com/microsoft/msquic/security/advisories/GHSA-w5f4-fx9m-m4q7
- https://nvd.nist.gov/vuln/detail/CVE-2026-105794
- https://github.com/microsoft/msquic/pull/6274
- https://github.com/microsoft/msquic/pull/6275
- https://github.com/microsoft/msquic/pull/6276
- https://github.com/microsoft/msquic/pull/6277
- https://github.com/microsoft/msquic/commit/0591586443cc73a2d2cfb679527d91a144b4a412
- https://github.com/microsoft/msquic/commit/508e811370df93e2ad848f5c78347d4fe4f65a91
- https://github.com/microsoft/msquic/commit/90fd45498bf9b506b8556fb407088688474d6c81
- https://github.com/microsoft/msquic/commit/a01333cf7c2659cce0ff03ef3f21e1ff15bb5b83
- https://github.com/microsoft/msquic/releases/tag/v2.4.20
- https://github.com/microsoft/msquic/releases/tag/v2.5.11
- https://github.com/microsoft/msquic/releases/tag/v2.6.1
- https://github.com/advisories/GHSA-w5f4-fx9m-m4q7