OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100665

HIGH · CVSS 7.5 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Versions of Netty prior to 4.2.18.Final are vulnerable due to an incomplete hostname verification fix in the QUIC certificate verification process, which allows attackers on the network path to present fraudulent certificate chains that bypass hostname authentication. This vulnerability can lead to man-in-the-middle attacks, compromising the security of QUIC clients. Organizations utilizing affected Netty versions, especially those handling sensitive data or operating in high-security environments, should prioritize updating to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100665
Severity
HIGH
CVSS
7.5
EPSS
0.29%

Original NVD Description

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.