VYPR
High severity7.5NVD Advisory· Published Sep 26, 2026

CVE-2026-100665

CVE-2026-100665

Description

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • Netty/Nettyllm-fuzzy
    Range: 4.2.11.Final - 4.2.17.Final

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.