MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
Package
Affected versions
< 2.4.20
>= 2.5.0, < 2.5.11
>= 2.6.0, < 2.6.1
Patched versions
2.4.20
2.5.11
2.6.1
Description
Published by the National Vulnerability Database
Oct 6, 2026
Published to the GitHub Advisory Database
Oct 6, 2026
Reviewed
Oct 6, 2026
Last updated
Oct 6, 2026
Summary
Improper TLS hostname verification allows a man-in-the-middle (MITM) attack on MsQuic.
Details
Only MsQuic with the OpenSSL and QuicTLS TLS backends is affected (the Schannel backend is not affected).
Patches
2.6.1, 2.5.11, and 2.4.20
Impact
An on-path attacker could spoof a server identity by using a certificate that doesn't match the intended target server hostname.
References