Product
Netty's netty-handler library fails to perform TLS hostname verification when using the OpenSSL provider on Java 25+ systems, enabling potential man-in-the-middle attacks.