Product
The MsQuic library using OpenSSL or QuicTLS backends fails to perform proper TLS hostname verification, enabling on-path attackers to perform man-in-the-middle (MITM) attacks and spoof server identities.