Disclosure summary
MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can therefore present a certificate that does not match the intended target hostname and spoof the server in a man-in-the-middle attack. The Schannel backend is not affected. This issue is fixed in versions 2.4.20, 2.5.11, and 2.6.1.
Source-reported weakness categories
CWE-295
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-w5f4-fx9m-m4q7
Open original source · Updated Oct 06, 2026
MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
Source severity: CRITICAL / 9.1
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| nuget | Microsoft.Native.Quic.MsQuic.OpenSSL | < 2.4.20 | 2.4.20 |
| nuget | Microsoft.Native.Quic.MsQuic.OpenSSL | >= 2.5.0, < 2.5.11 | 2.5.11 |
| nuget | Microsoft.Native.Quic.MsQuic.OpenSSL | >= 2.6.0, < 2.6.1 | 2.6.1 |
NIST National Vulnerability Database · NVD-CVE-2026-105794
Open original source · Updated Oct 06, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
- NIST NVD record
- CVE Program record
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
- github.com
PUBLISHED 2026-10-06T11:17:16-04:00
MODIFIED 2026-10-06T11:17:16-04:00
INGESTED 2026-10-06T11:45:53-04:00