CVE-2026-100665
7.5 HIGHpublic exploit availablePublished 2026-09-26 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-295
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-100551PoC
- MEDIUMCVE-2026-100701PoC
- HIGHCVE-2026-100835PoC
- HIGHCVE-2026-101916PoC
- MEDIUMCVE-2026-16792
- LOWCVE-2026-18173
- HIGHCVE-2026-40539
- UNSCOREDCVE-2026-63374PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.