---
id: CVE-2026-105794
title: >-
  MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed
  to C, C++, C#, and Rust
summary: >-
  MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed
  to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients
  using the OpenSSL or QuicTLS TLS backend do not properly verify that a server
  certi…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-295
vendor: Microsoft
product: Microsoft.Native.Quic.MsQuic.OpenSSL
affected:
  - Microsoft.Native.Quic.MsQuic.OpenSSL < 2.4.20
  - 'Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.5.0, < 2.5.11'
  - 'Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.6.0, < 2.6.1'
patched:
  - Microsoft.Native.Quic.MsQuic.OpenSSL 2.4.20
  - Microsoft.Native.Quic.MsQuic.OpenSSL 2.5.11
  - Microsoft.Native.Quic.MsQuic.OpenSSL 2.6.1
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T16:00:36.547'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105794'
references:
  - url: >-
      https://github.com/microsoft/msquic/commit/0591586443cc73a2d2cfb679527d91a144b4a412
    label: security-advisories@github.com
  - url: >-
      https://github.com/microsoft/msquic/commit/508e811370df93e2ad848f5c78347d4fe4f65a91
    label: security-advisories@github.com
  - url: >-
      https://github.com/microsoft/msquic/commit/90fd45498bf9b506b8556fb407088688474d6c81
    label: security-advisories@github.com
  - url: >-
      https://github.com/microsoft/msquic/commit/a01333cf7c2659cce0ff03ef3f21e1ff15bb5b83
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/msquic/pull/6274'
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/msquic/pull/6275'
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/msquic/pull/6276'
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/msquic/pull/6277'
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/msquic/releases/tag/v2.4.20'
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/msquic/releases/tag/v2.5.11'
    label: security-advisories@github.com
  - url: 'https://github.com/microsoft/msquic/releases/tag/v2.6.1'
    label: security-advisories@github.com
  - url: >-
      https://github.com/microsoft/msquic/security/advisories/GHSA-w5f4-fx9m-m4q7
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105794'
  - url: 'https://github.com/advisories/GHSA-w5f4-fx9m-m4q7'
tags:
  - nvd
  - ghsa
  - nuget
  - cve.org
aliases:
  - GHSA-w5f4-fx9m-m4q7
ecosystem: nuget
cvssSource: cna
ingestedAt: '2026-10-06T15:01:49.306Z'
---

## Overview

MsQuic is a cross-platform C implementation of the IETF QUIC protocol exposed to C, C++, C#, and Rust. Prior to 2.4.20, 2.5.11, and 2.6.1, MsQuic clients using the OpenSSL or QuicTLS TLS backend do not properly verify that a server certificate matches the intended target server hostname. An on-path attacker can therefore present a certificate that does not match the intended target hostname and spoof the server in a man-in-the-middle attack. The Schannel backend is not affected. This issue is fixed in versions 2.4.20, 2.5.11, and 2.6.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-105794)

Affected packages:

- `Microsoft.Native.Quic.MsQuic.OpenSSL < 2.4.20`
- `Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.5.0, < 2.5.11`
- `Microsoft.Native.Quic.MsQuic.OpenSSL >= 2.6.0, < 2.6.1`

Patched in:

- `Microsoft.Native.Quic.MsQuic.OpenSSL 2.4.20`
- `Microsoft.Native.Quic.MsQuic.OpenSSL 2.5.11`
- `Microsoft.Native.Quic.MsQuic.OpenSSL 2.6.1`

Source: https://github.com/advisories/GHSA-w5f4-fx9m-m4q7
