Database/Control plane, storage & DevOps
MsQuic: QUIC clients on the OpenSSL backend do not verify the server certificate hostname
Impact
MsQuic clients built against the OpenSSL or QuicTLS backend accept a server certificate that does not match the hostname they intended to reach. An on-path attacker can present any certificate it can get signed and impersonate the server, giving a full man-in-the-middle over the QUIC session - credentials, tokens and payloads in both directions. This matters wherever MsQuic carries agent, telemetry or data-transfer traffic between a fleet and its control services, because the client's own trust check is what was supposed to stop this. The Schannel backend is not affected, so Windows builds using Schannel are out of scope.
Who can reach it
Network attacker in an on-path position between an MsQuic client and the server it is dialing. No authentication required.
What to do
Upgrade MsQuic to 2.4.20, 2.5.11 or 2.6.1 depending on your branch, then rebuild and restart every client that embeds it - the fix is in the library, so a dependency bump alone is not enough until consumers are relinked and redeployed.
References
Related entries
- Grafana MCP Server: caller-controlled X-Grafana-URL header turns grafana_api_request into a full SSRF primitiveCVE-2026-19516 · mcp-grafana (Grafana MCP Server, X-Grafana-URL destination control)Critical
- Apache CloudStack Proxmox extension (cross-tenant instance access): The extension keys CloudStack instances to ProxmoxCVE-2026-25199 · Apache CloudStack Proxmox extension (cross-tenant instance access)Critical
- BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gateways: A runCVE-2026-41475 · BACnet Stack open-source C library (bacnet-stack) embedded in third-party controllers and gatewaysCritical
- Ceph Monitor: any read-only CephX user can dump the config-key store, including cephadm's cluster-wide SSH keyCVE-2026-50152 · Ceph Monitor (MMonSubscribe config-key store authorization)Critical
- Apache Airflow FAB provider: Azure AD id_token issuer and audience unchecked, any tenant can log inCVE-2026-75156 · Apache Airflow FAB provider (Azure AD OAuth id_token issuer/audience validation)Critical
- Airflow Keycloak provider: Keycloak tokens from unsigned cookies are not bound to the session identityCVE-2026-76186 · Apache Airflow Keycloak provider (session identity vs. Keycloak access/refresh token binding)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.