CVE-2026-100665

Source
https://cve.org/CVERecord?id=CVE-2026-100665
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100665.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100665
Aliases
  • GHSA-mj35-3qqm-q387
Published
2026-09-26T13:23:31Z
Modified
2026-09-29T08:06:46Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Netty 4.2.11 through 4.2.17 QUIC Hostname Verification Bypass
Details

Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certificate verification path when using a plain X509TrustManager. The BoringSSLCertificateVerifyCallback discards the SSLEngine for plain trust managers, preventing endpoint identification from running even when HTTPS verification is configured. Attackers on the network path can present a certificate chain for the wrong hostname that the plain trust manager accepts, bypassing hostname authentication for QUIC clients.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-295"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100665.json"
}
References

Affected packages

Git / github.com/netty/netty

Affected ranges

Type
GIT
Repo
https://github.com/netty/netty
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "4.2.11.Final"
        },
        {
            "fixed":  "4.2.18.Final"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

netty-4.*
netty-4.2.11.Final
netty-4.2.12.Final
netty-4.2.13.Final
netty-4.2.14.Final
netty-4.2.15.Final
netty-4.2.16.Final
netty-4.2.17.Final
Other
netty-clang-bin

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100665.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "154869084831111022853806201196128528812",
                "208600710400137741040111491283853269276",
                "168647826034034474017709151166628438804",
                "66289982268351173909109911755158266812",
                "255476222891084277626131038497353273948",
                "83834879282253274945221179567253752841",
                "314860779219010993803570014595166371680",
                "308371687883116925817085629798254608981",
                "125031063421281806976392959200490464478",
                "141965260724922115976931570939887847605",
                "60956740356194625212075986054472028827",
                "61671546356182263661059354045569345911",
                "215857659453420964288804171507745586587",
                "223873169913841514791466199455654952347",
                "20610135678331918589370701094205946357",
                "279440954898851114651708966179559583284",
                "179069934368587692646581435307845239200",
                "146419087942096387368918617746288726503",
                "136249797623624094057110392335990861697",
                "74496224567601293282918511804497247118",
                "330406792600762027102646329773776034222",
                "86926758104830016109319726695642207256",
                "36974874867940605914672957046553286804",
                "336453024329179099448562652788799559279",
                "289760229398566804129228150808281103997",
                "247576988496464487839894645084163420194",
                "191664817804152709866283106455989317901",
                "108587633537507210242609878158511307392",
                "108587633537507210242609878158511307392"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-100665-566b5b10",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe",
        "target":  {
            "file":  "handler/src/main/java/io/netty/handler/ssl/util/SimpleTrustManagerFactory.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "7820332042966766048328893441621138689",
                "30406650284505601747185511090336331417",
                "10026550756253014692577547395435110176",
                "55120756050436380076450744412346429477",
                "172997312373889519119787666710627131261",
                "64000145426482088724712150504930422352",
                "314878502388607914865960896957079020925",
                "339360943031719067994253063999458347415",
                "24845980083348140916716538590187517894",
                "153585231130582869228881207243513707984"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-100665-7b003359",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe",
        "target":  {
            "file":  "handler/src/main/java/io/netty/handler/ssl/util/InsecureTrustManagerFactory.java"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "46738205650655798884494635217132416599",
            "length":  215
        },
        "id":  "CVE-2026-100665-7bda8630",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe",
        "target":  {
            "file":  "handler/src/main/java/io/netty/handler/ssl/util/SimpleTrustManagerFactory.java",
            "function":  "engineGetTrustManagers"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "285718327012452783865166146066857809034",
            "length":  237
        },
        "id":  "CVE-2026-100665-9cb17f84",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/netty/netty/commit/09e72c4fd8007277121ed48db63a124b112b96fe",
        "target":  {
            "file":  "handler/src/main/java/io/netty/handler/ssl/util/SimpleTrustManagerFactory.java",
            "function":  "wrapIfNeeded"
        }
    }
]
vanir_signatures_modified
"2026-09-29T08:06:46Z"