CVE-2026-100665: Netty
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.
Affected products
- Netty Netty: from 4.2.11.Final, before 4.2.18.Final (fixed in 4.2.18.Final)
Published 2026-09-26. Last modified 2026-10-02.