<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>MsQuic (&lt; 2.4.20, 2.5.0-2.5.10, 2.6.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/msquic--2.4.20-2.5.0-2.5.10-2.6.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 00:44:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/msquic--2.4.20-2.5.0-2.5.10-2.6.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Improper Certificate Validation in MsQuic OpenSSL Backend</title><link>https://feed.craftedsignal.io/briefs/2026-10-msquic-tls-validation/</link><pubDate>Wed, 07 Oct 2026 00:44:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-msquic-tls-validation/</guid><description>The MsQuic library using OpenSSL or QuicTLS backends fails to perform proper TLS hostname verification, enabling on-path attackers to perform man-in-the-middle (MITM) attacks and spoof server identities.</description><content:encoded><![CDATA[<p>MsQuic, a cross-platform implementation of the IETF QUIC protocol, contains a vulnerability in its certificate validation logic when using the OpenSSL or QuicTLS TLS backends. The flaw, tracked as CVE-2026-105794, arises from improper TLS hostname verification. This issue affects specific versions of the Microsoft.Native.Quic.MsQuic.OpenSSL NuGet package, including versions below 2.4.20, those between 2.5.0 and 2.5.10, and those between 2.6.0 and 2.6.0.</p>
<p>When an application utilizing an affected version of MsQuic initiates a QUIC connection, the library fails to ensure that the certificate presented by the remote peer matches the expected hostname. This vulnerability allows an on-path attacker to intercept QUIC traffic and present a fraudulent certificate that the client will accept as valid, thereby facilitating a man-in-the-middle (MITM) attack. The Schannel backend is confirmed to be unaffected. Defenders should prioritize updating applications that bundle or dynamically link against the impacted MsQuic versions to the patched releases: 2.4.20, 2.5.11, or 2.6.1.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a man-in-the-middle attacker to intercept, inspect, or modify encrypted traffic between the client and the server. This compromises the integrity and confidentiality of the QUIC-based communications, potentially leading to the theft of sensitive session data, credentials, or other payloads transmitted over the connection. The impact is significant for any enterprise application relying on MsQuic for secure, performance-critical QUIC transport.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize updating all applications and services utilizing the vulnerable Microsoft.Native.Quic.MsQuic.OpenSSL NuGet package to the patched versions: 2.4.20, 2.5.11, or 2.6.1. Perform a software composition analysis (SCA) scan to identify instances of the vulnerable package within your environment.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>tls</category><category>quic</category><category>mitm</category></item></channel></rss>