{"id":"CVE-2026-105794","title":"MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust","summary":"MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certi…","severity":"critical","cvss":9.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-295"],"vendor":"Microsoft","product":"Microsoft.Native.Quic.MsQuic.OpenSSL","affected":["Microsoft.Native.Quic.MsQuic.OpenSSL < 2.4.20","Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.5.0, < 2.5.11","Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.6.0, < 2.6.1"],"patched":["Microsoft.Native.Quic.MsQuic.OpenSSL 2.4.20","Microsoft.Native.Quic.MsQuic.OpenSSL 2.5.11","Microsoft.Native.Quic.MsQuic.OpenSSL 2.6.1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T16:00:36.547","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105794","references":[{"url":"https://github.com/microsoft/msquic/commit/0591586443cc73a2d2cfb679527d91a144b4a412","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/commit/508e811370df93e2ad848f5c78347d4fe4f65a91","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/commit/90fd45498bf9b506b8556fb407088688474d6c81","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/commit/a01333cf7c2659cce0ff03ef3f21e1ff15bb5b83","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/pull/6274","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/pull/6275","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/pull/6276","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/pull/6277","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/releases/tag/v2.4.20","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/releases/tag/v2.5.11","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/releases/tag/v2.6.1","label":"security-advisories@github.com"},{"url":"https://github.com/microsoft/msquic/security/advisories/GHSA-w5f4-fx9m-m4q7","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105794"},{"url":"https://github.com/advisories/GHSA-w5f4-fx9m-m4q7"}],"tags":["nvd","ghsa","nuget","cve.org"],"aliases":["GHSA-w5f4-fx9m-m4q7"],"ecosystem":"nuget","cvssSource":"cna","ingestedAt":"2026-10-06T15:01:49.306Z","slug":"CVE-2026-105794","body":"## Overview\n\nMsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can therefore present a certificate that does not match the intended target hostname and spoof the server in a man-in-the-middle attack. The Schannel backend is not affected. This issue is fixed in versions 2.4.20, 2.5.11, and 2.6.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-105794)\n\nAffected packages:\n\n- `Microsoft.Native.Quic.MsQuic.OpenSSL < 2.4.20`\n- `Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.5.0, < 2.5.11`\n- `Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.6.0, < 2.6.1`\n\nPatched in:\n\n- `Microsoft.Native.Quic.MsQuic.OpenSSL 2.4.20`\n- `Microsoft.Native.Quic.MsQuic.OpenSSL 2.5.11`\n- `Microsoft.Native.Quic.MsQuic.OpenSSL 2.6.1`\n\nSource: https://github.com/advisories/GHSA-w5f4-fx9m-m4q7","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}