CPE
Netty versions 4.2.11.Final through 4.2.17.Final contain an incomplete hostname verification fix in the QUIC certificate verification path, allowing network-adjacent attackers to bypass certificate validation and conduct man-in-the-middle attacks.