CVE-2026-105794
Awaiting Analysis Awaiting Analysis - Queue

MsQuic TLS Certificate Verification Bypass

Vulnerability report for CVE-2026-105794, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can therefore present a certificate that does not match the intended target hostname and spoof the server in a man-in-the-middle attack. The Schannel backend is not affected. This issue is fixed in versions 2.4.20, 2.5.11, and 2.6.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
microsoft msquic < 2.4.20
microsoft msquic >= 2.5.0, < 2.5.11
microsoft msquic >= 2.6.0, < 2.6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

MsQuic is a library implementing the QUIC protocol. Prior to versions 2.4.20, 2.5.11, and 2.6.1, clients using OpenSSL or QuicTLS backends failed to verify if a server certificate matched the intended hostname. This allows an attacker on the network path to spoof the server by presenting a mismatched certificate in a man-in-the-middle attack.

Detection Guidance

Detecting this vulnerability requires checking the MsQuic version in use. If your system uses MsQuic with OpenSSL or QuicTLS backend and the version is below 2.4.20, 2.5.11, or 2.6.1, it is vulnerable. Commands to check the version depend on the application using MsQuic. For example, in Windows, you can check via PowerShell: Get-Command msquic | Select-Object Version. On Linux, use: dpkg -l | grep msquic or rpm -qa | grep msquic.

Additionally, inspect network traffic for unexpected certificate mismatches or man-in-the-middle indicators using tools like Wireshark or tcpdump.

Impact Analysis

An attacker could intercept and alter communications between you and the server, potentially stealing sensitive data like login credentials or personal information. This affects any application using MsQuic with OpenSSL or QuicTLS backends before the patched versions.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or health data, violating GDPR and HIPAA requirements for data protection and confidentiality. Organizations using affected MsQuic versions may face compliance violations and penalties.

Mitigation Strategies

Upgrade MsQuic to version 2.4.20, 2.5.11, or 2.6.1 or later immediately. If using OpenSSL or QuicTLS backend, switch to the Schannel backend if possible. Disable vulnerable configurations until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105794. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart