CVE-2026-100665: Netty

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.

Affected products

  • Netty Netty: from 4.2.11.Final, before 4.2.18.Final (fixed in 4.2.18.Final)

Published 2026-09-26. Last modified 2026-10-02.