GHSA-w5f4-fx9m-m4q7Critical

MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

Improper TLS hostname verification allows a man-in-the-middle (MITM) attack on MsQuic.

Details

Only MsQuic with the OpenSSL and QuicTLS TLS backends is affected (the Schannel backend is not affected).

Patches

2.6.1, 2.5.11, and 2.4.20

Impact

An on-path attacker could spoof a server identity by using a certificate that doesn't match the intended target server hostname.

🎯 Affected products3

  • nuget/Microsoft.Native.Quic.MsQuic.OpenSSL:< 2.4.20
  • nuget/Microsoft.Native.Quic.MsQuic.OpenSSL:>= 2.5.0, < 2.5.11
  • nuget/Microsoft.Native.Quic.MsQuic.OpenSSL:>= 2.6.0, < 2.6.1

🔗 References (14)