{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftmsquic/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:msquic:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-105794"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MsQuic (\u003c 2.4.20, 2.5.0-2.5.10, 2.6.0)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","tls","quic","mitm"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMsQuic, a cross-platform implementation of the IETF QUIC protocol, contains a vulnerability in its certificate validation logic when using the OpenSSL or QuicTLS TLS backends. The flaw, tracked as CVE-2026-105794, arises from improper TLS hostname verification. This issue affects specific versions of the Microsoft.Native.Quic.MsQuic.OpenSSL NuGet package, including versions below 2.4.20, those between 2.5.0 and 2.5.10, and those between 2.6.0 and 2.6.0.\u003c/p\u003e\n\u003cp\u003eWhen an application utilizing an affected version of MsQuic initiates a QUIC connection, the library fails to ensure that the certificate presented by the remote peer matches the expected hostname. This vulnerability allows an on-path attacker to intercept QUIC traffic and present a fraudulent certificate that the client will accept as valid, thereby facilitating a man-in-the-middle (MITM) attack. The Schannel backend is confirmed to be unaffected. Defenders should prioritize updating applications that bundle or dynamically link against the impacted MsQuic versions to the patched releases: 2.4.20, 2.5.11, or 2.6.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a man-in-the-middle attacker to intercept, inspect, or modify encrypted traffic between the client and the server. This compromises the integrity and confidentiality of the QUIC-based communications, potentially leading to the theft of sensitive session data, credentials, or other payloads transmitted over the connection. The impact is significant for any enterprise application relying on MsQuic for secure, performance-critical QUIC transport.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating all applications and services utilizing the vulnerable Microsoft.Native.Quic.MsQuic.OpenSSL NuGet package to the patched versions: 2.4.20, 2.5.11, or 2.6.1. Perform a software composition analysis (SCA) scan to identify instances of the vulnerable package within your environment.\u003c/p\u003e\n","date_modified":"2026-10-07T00:44:50Z","date_published":"2026-10-07T00:44:50Z","id":"https://feed.craftedsignal.io/briefs/2026-10-msquic-tls-validation/","summary":"The MsQuic library using OpenSSL or QuicTLS backends fails to perform proper TLS hostname verification, enabling on-path attackers to perform man-in-the-middle (MITM) attacks and spoof server identities.","title":"Improper Certificate Validation in MsQuic OpenSSL Backend","url":"https://feed.craftedsignal.io/briefs/2026-10-msquic-tls-validation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:microsoft:msquic:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}