CVE-2026-105794: MsQuic: Improper Certificate Validation in Microsoft.Native.Quic.MsQuic.OpenSSL
Summary
Improper TLS hostname verification allows a man-in-the-middle (MITM) attack on MsQuic.
Details
Only MsQuic with the OpenSSL and QuicTLS TLS backends is affected (the Schannel backend is not affected).
Patches
2.6.1, 2.5.11, and 2.4.20
Impact
An on-path attacker could spoof a server identity by using a certificate that doesn't match the intended target server hostname.
Other sources
MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can therefore present a certificate that does not match the intended target hostname and spoof the server in a man-in-the-middle attack. The Schannel backend is not affected. This issue is fixed in versions 2.4.20, 2.5.11, and 2.6.1.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Microsoft.Native.Quic.MsQuic.OpenSSLto a version that resolves this vulnerability.Fixed in 2.6.1 - Upgrade
Upgrade
nuget/Microsoft.Native.Quic.MsQuic.OpenSSLto a version that resolves this vulnerability.Fixed in 2.5.11 - Upgrade
Upgrade
nuget/Microsoft.Native.Quic.MsQuic.OpenSSLto a version that resolves this vulnerability.Fixed in 2.4.20 - Upgrade
Upgrade
MsQuicto a version that resolves this vulnerability.Fixed in 2.4.20 - Upgrade
Upgrade
MsQuicto a version that resolves this vulnerability.Fixed in 2.5.11 - Upgrade
Upgrade
MsQuicto a version that resolves this vulnerability.Fixed in 2.6.1