OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-105794: MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL

GitHub Advisories · officialPublished Oct 6, 2026Risk 50/100

# Summary Improper TLS hostname verification allows a man-in-the-middle (MITM) attack on MsQuic. # Details Only MsQuic with the OpenSSL and QuicTLS TLS backends is affected (the Schannel backend is not affected). ## Patches 2.6.1, 2.5.11, and 2.4.20 # Impact An on-path attacker could spoof a server identity by using a certificate that doesn't match the intended target server hostname.

Upgrade affected packages to a patched version: Microsoft.Native.Quic.MsQuic.OpenSSL 2.4.20, Microsoft.Native.Quic.MsQuic.OpenSSL 2.5.11, Microsoft.Native.Quic.MsQuic.OpenSSL 2.6.1.

Vendor
Not specified
Product
Microsoft.Native.Quic.MsQuic.OpenSSL
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source