Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-295"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100665.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100665.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"154869084831111022853806201196128528812",
"208600710400137741040111491283853269276",
"168647826034034474017709151166628438804",
"66289982268351173909109911755158266812",
"255476222891084277626131038497353273948",
"83834879282253274945221179567253752841",
"314860779219010993803570014595166371680",
"308371687883116925817085629798254608981",
"125031063421281806976392959200490464478",
"141965260724922115976931570939887847605",
"60956740356194625212075986054472028827",
"61671546356182263661059354045569345911",
"215857659453420964288804171507745586587",
"223873169913841514791466199455654952347",
"20610135678331918589370701094205946357",
"279440954898851114651708966179559583284",
"179069934368587692646581435307845239200",
"146419087942096387368918617746288726503",
"136249797623624094057110392335990861697",
"74496224567601293282918511804497247118",
"330406792600762027102646329773776034222",
"86926758104830016109319726695642207256",
"36974874867940605914672957046553286804",
"336453024329179099448562652788799559279",
"289760229398566804129228150808281103997",
"247576988496464487839894645084163420194",
"191664817804152709866283106455989317901",
"108587633537507210242609878158511307392",
"108587633537507210242609878158511307392"
],
"threshold": 0.9
},
"id": "CVE-2026-100665-566b5b10",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe",
"target": {
"file": "handler/src/main/java/io/netty/handler/ssl/util/SimpleTrustManagerFactory.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"7820332042966766048328893441621138689",
"30406650284505601747185511090336331417",
"10026550756253014692577547395435110176",
"55120756050436380076450744412346429477",
"172997312373889519119787666710627131261",
"64000145426482088724712150504930422352",
"314878502388607914865960896957079020925",
"339360943031719067994253063999458347415",
"24845980083348140916716538590187517894",
"153585231130582869228881207243513707984"
],
"threshold": 0.9
},
"id": "CVE-2026-100665-7b003359",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe",
"target": {
"file": "handler/src/main/java/io/netty/handler/ssl/util/InsecureTrustManagerFactory.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "46738205650655798884494635217132416599",
"length": 215
},
"id": "CVE-2026-100665-7bda8630",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe",
"target": {
"file": "handler/src/main/java/io/netty/handler/ssl/util/SimpleTrustManagerFactory.java",
"function": "engineGetTrustManagers"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "285718327012452783865166146066857809034",
"length": 237
},
"id": "CVE-2026-100665-9cb17f84",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe",
"target": {
"file": "handler/src/main/java/io/netty/handler/ssl/util/SimpleTrustManagerFactory.java",
"function": "wrapIfNeeded"
}
}
]
"2026-09-29T08:06:46Z"