Vulnerability GHSA-w5f4-fx9m-m4q7
Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 hours ago
October 06, 2026 at 03:33 PM UTC
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
1.8.0
1.8.0
Summary
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
Details
Summary
Improper TLS hostname verification allows a man-in-the-middle (MITM) attack on MsQuic.
Details
Only MsQuic with the OpenSSL and QuicTLS TLS backends is affected (the Schannel backend is not affected).
Patches
2.6.1, 2.5.11, and 2.4.20
Impact
An on-path attacker could spoof a server identity by using a certificate that doesn't match the intended target server hostname.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
27 days ago
Microsoft QUIC: Remote Code Execution Vulnerability
1.8.0 GHSA-92f5-vc22-8j33
1.8.0 GHSA-92f5-vc22-8j33
Critical
5 months ago
MsQuic has a Remote Elevation of Privilege Vulnerability
1.8.0 GHSA-gvvw-8j96-8g5r
1.8.0 GHSA-gvvw-8j96-8g5r
High Risk
2 years ago
Remote Denial of Service Vulnerability in Microsoft QUIC
1.8.0 GHSA-2x7m-gf85-3745
1.8.0 GHSA-2x7m-gf85-3745
High Risk
2 years ago
MsQuic Remote Denial of Service Vulnerability
1.8.0 GHSA-fr44-546p-7xcp
1.8.0 GHSA-fr44-546p-7xcp
High Risk
2 years ago
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
1.8.0 GHSA-xh5m-8qqp-c5x7
1.8.0 GHSA-xh5m-8qqp-c5x7
Impacted packages
Timeline
Published
2 hours ago
October 06, 2026 at 03:33 PM UTC
Last Modified
2 hours ago
October 06, 2026 at 03:46 PM UTC