GPU VulnDB

Database/Control plane, storage & DevOps

MsQuic: QUIC clients on the OpenSSL backend do not verify the server certificate hostname

CVSS 9.1CVE-2026-105794Control plane, storage & DevOpscurated

Impact

MsQuic clients built against the OpenSSL or QuicTLS backend accept a server certificate that does not match the hostname they intended to reach. An on-path attacker can present any certificate it can get signed and impersonate the server, giving a full man-in-the-middle over the QUIC session - credentials, tokens and payloads in both directions. This matters wherever MsQuic carries agent, telemetry or data-transfer traffic between a fleet and its control services, because the client's own trust check is what was supposed to stop this. The Schannel backend is not affected, so Windows builds using Schannel are out of scope.

Who can reach it

Network attacker in an on-path position between an MsQuic client and the server it is dialing. No authentication required.

What to do

Upgrade MsQuic to 2.4.20, 2.5.11 or 2.6.1 depending on your branch, then rebuild and restart every client that embeds it - the fix is in the library, so a dependency bump alone is not enough until consumers are relinked and redeployed.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.