{"id":"GHSA-w5f4-fx9m-m4q7","summary":"MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL","details":"# Summary\n\nImproper TLS hostname verification allows a man-in-the-middle (MITM) attack on MsQuic. \n\n# Details\n\nOnly MsQuic with the OpenSSL and QuicTLS TLS backends is affected (the Schannel backend is not affected).\n\n## Patches\n\n2.6.1, 2.5.11, and 2.4.20\n\n# Impact\n\nAn on-path attacker could spoof a server identity by using a certificate that doesn't match the intended target server hostname.","aliases":["CVE-2026-105794"],"modified":"2026-10-06T15:46:49.195357428Z","published":"2026-10-06T15:33:08Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-06T15:33:08Z","nvd_published_at":"2026-10-06T15:17:16Z","cwe_ids":["CWE-295"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/microsoft/msquic/security/advisories/GHSA-w5f4-fx9m-m4q7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105794"},{"type":"WEB","url":"https://github.com/microsoft/msquic/pull/6274"},{"type":"WEB","url":"https://github.com/microsoft/msquic/pull/6275"},{"type":"WEB","url":"https://github.com/microsoft/msquic/pull/6276"},{"type":"WEB","url":"https://github.com/microsoft/msquic/pull/6277"},{"type":"WEB","url":"https://github.com/microsoft/msquic/commit/0591586443cc73a2d2cfb679527d91a144b4a412"},{"type":"WEB","url":"https://github.com/microsoft/msquic/commit/508e811370df93e2ad848f5c78347d4fe4f65a91"},{"type":"WEB","url":"https://github.com/microsoft/msquic/commit/90fd45498bf9b506b8556fb407088688474d6c81"},{"type":"WEB","url":"https://github.com/microsoft/msquic/commit/a01333cf7c2659cce0ff03ef3f21e1ff15bb5b83"},{"type":"PACKAGE","url":"https://github.com/microsoft/msquic"},{"type":"WEB","url":"https://github.com/microsoft/msquic/releases/tag/v2.4.20"},{"type":"WEB","url":"https://github.com/microsoft/msquic/releases/tag/v2.5.11"},{"type":"WEB","url":"https://github.com/microsoft/msquic/releases/tag/v2.6.1"}],"affected":[{"package":{"name":"Microsoft.Native.Quic.MsQuic.OpenSSL","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.Native.Quic.MsQuic.OpenSSL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.20"}]}],"versions":["1.8.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-w5f4-fx9m-m4q7/GHSA-w5f4-fx9m-m4q7.json"}},{"package":{"name":"Microsoft.Native.Quic.MsQuic.OpenSSL","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.Native.Quic.MsQuic.OpenSSL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0"},{"fixed":"2.5.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-w5f4-fx9m-m4q7/GHSA-w5f4-fx9m-m4q7.json"}},{"package":{"name":"Microsoft.Native.Quic.MsQuic.OpenSSL","ecosystem":"NuGet","purl":"pkg:nuget/Microsoft.Native.Quic.MsQuic.OpenSSL"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.0"},{"fixed":"2.6.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-w5f4-fx9m-m4q7/GHSA-w5f4-fx9m-m4q7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}