Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100665— Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass

Quick assessment

Affected
netty netty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Netty 4.2.11.Final 之前至 4.2.18.Final 版本之间,当使用纯 X509TrustManager 时,QUIC 证书验证路径中的主机名验证修复不完整。BoringSSLCertificateVerifyCallback 会舍弃用于纯信任管理器的 SSLEngine,导致即使配置了 HTTPS 验证,也无法运行端点标识验证。网络路径上的攻击者可以提供针对错误主机名的证书链,该证书链会被纯信任管理器接受,从而绕过对 QUIC 客户端的主机名认证。

CVSS 7.5 · High EPSS 0.29% · P19

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100665

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
netty netty 4.2.11.Final ~ 4.2.18.Final -

II. Public POCs for CVE-2026-100665

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100665

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100665 (1)

Other References for CVE-2026-100665 (3)

Same Patch Batch · netty · 2026-09-26 · 12 CVEs total

CVE-2026-100655 7.5 HIGH Netty before 4.1.138.Final Denial of Service via SpdySessionHandler
CVE-2026-100663 7.5 HIGH Netty HTTP/1 CONNECT authority-form mistranslated to malformed HTTP/3
CVE-2026-100656 7.5 HIGH Netty HttpServerCodec Unbounded Queue Growth via HTTP/1.1 Pipelining
CVE-2026-100661 7.5 HIGH Netty HTTP/3 QPACK Prefixed Integer DoS via Unbounded Accumulation
CVE-2026-100660 7.5 HIGH Netty before 4.2.18.Final QpackEncoder Unbounded Memory Retention
CVE-2026-100662 7.5 HIGH Netty HTTP/3 QPACK encoder-stream unbounded memory exhaustion DoS
CVE-2026-100664 7.5 HIGH Netty 4.2.2 through 4.2.17 HTTP/1 Host Header Authority Confusion
CVE-2026-100657 7.5 HIGH Netty before 4.1.138.Final ByteBuf Leak in StompSubframeDecoder
CVE-2026-100666 7.3 HIGH Netty 4.2.0 through 4.2.16 Response Desynchronization via HttpServerCodec
CVE-2026-100659 6.5 MEDIUM Netty 4.2.0 through 4.2.17 HTTP/3 Request Routing Bypass
CVE-2026-100658 5.3 MEDIUM Netty before 4.1.138.Final Denial of Service via WebSocketServerExtensionHandler

IV. Related Vulnerabilities

V. Comments for CVE-2026-100665

No comments yet


Leave a comment