在 Netty 4.2.11.Final 之前至 4.2.18.Final 版本之间,当使用纯 X509TrustManager 时,QUIC 证书验证路径中的主机名验证修复不完整。BoringSSLCertificateVerifyCallback 会舍弃用于纯信任管理器的 SSLEngine,导致即使配置了 HTTPS 验证,也无法运行端点标识验证。网络路径上的攻击者可以提供针对错误主机名的证书链,该证书链会被纯信任管理器接受,从而绕过对 QUIC 客户端的主机名认证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100655 | 7.5 HIGH | Netty before 4.1.138.Final Denial of Service via SpdySessionHandler |
| CVE-2026-100663 | 7.5 HIGH | Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3 |
| CVE-2026-100656 | 7.5 HIGH | Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining |
| CVE-2026-100661 | 7.5 HIGH | Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation |
| CVE-2026-100660 | 7.5 HIGH | Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention |
| CVE-2026-100662 | 7.5 HIGH | Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS |
| CVE-2026-100664 | 7.5 HIGH | Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion |
| CVE-2026-100657 | 7.5 HIGH | Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder |
| CVE-2026-100666 | 7.3 HIGH | Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec |
| CVE-2026-100659 | 6.5 MEDIUM | Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass |
| CVE-2026-100658 | 5.3 MEDIUM | Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler |
No comments yet