Improper Certificate Validation Affecting io.netty:netty-codec-classes-quic package, versions [4.2.11.Final,4.2.18.Final)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.29% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-IONETTY-20154418
  • published27 Sept 2026
  • disclosed26 Sept 2026
  • creditRex Liu

Introduced: 26 Sep 2026

NewCVE-2026-100665  (opens in a new tab)
CWE-295  (opens in a new tab)

How to fix?

Upgrade io.netty:netty-codec-classes-quic to version 4.2.18.Final or higher.

Overview

Affected versions of this package are vulnerable to Improper Certificate Validation in the verify(...) method of BoringSSLCertificateVerifyCallback, which for a plain X509TrustManager invokes only the two-argument checkServerTrusted(chain, authType) overload, dropping the QuicheQuicSslEngine that carries the peer host and SSLParameters so the configured HTTPS endpoint identification is never enforced. An attacker can impersonate the intended server by answering the connection with a certificate chain that the application's trust manager accepts but that is not valid for the requested peer host, which the QUIC client then accepts. This requires a client built through QuicSslContextBuilder.forClient() with a plain X509TrustManager supplied rather than an X509ExtendedTrustManager, and the endpoint identification algorithm set to HTTPS.

Workaround

This vulnerability can be avoided by supplying an X509ExtendedTrustManager instead of a plain X509TrustManager, so the verification path retains the engine carrying the peer host and applies the configured endpoint identification.

Note: This is a bypass of the fix for the vulnerability described in CVE-2026-50010.

CVSS Base Scores

version 4.0
version 3.1