Vulnerability GHSA-w5f4-fx9m-m4q7

Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 hours ago
October 06, 2026 at 03:33 PM UTC
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
1.8.0
1.8.0

Summary

MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL

Details

Summary

Improper TLS hostname verification allows a man-in-the-middle (MITM) attack on MsQuic.

Details

Only MsQuic with the OpenSSL and QuicTLS TLS backends is affected (the Schannel backend is not affected).

Patches

2.6.1, 2.5.11, and 2.4.20

Impact

An on-path attacker could spoof a server identity by using a certificate that doesn't match the intended target server hostname.

Timeline

Published
2 hours ago
October 06, 2026 at 03:33 PM UTC
Last Modified
2 hours ago
October 06, 2026 at 03:46 PM UTC