MsQuic OpenSSL/QuicTLS Backend: Improper Certificate Validation Enables MITM (CVE-2026-105794)
What Happened
Microsoft disclosed a GitHub Security Advisory (GHSA-w5f4-fx9m-m4q7, CVE-2026-105794) affecting Microsoft.Native.Quic.MsQuic.OpenSSL. According to the advisory, MsQuic improperly verifies the TLS hostname when using the OpenSSL or QuicTLS backends. The Schannel backend is explicitly called out as not affected. The flaw allows an on-path attacker to spoof a server identity by presenting a certificate that does not match the intended target hostname, enabling a man-in-the-middle (MITM) attack against QUIC connections. Fixes are available in versions 2.6.1, 2.5.11, and 2.4.20. Exploit status is listed as PoC-public; no CVSS score has been published yet.
Why It Matters
MsQuic is Microsoft's QUIC implementation and is embedded in products and libraries that negotiate QUIC/HTTP-3 connections. Any consumer that builds with the OpenSSL or QuicTLS TLS backend — rather than Schannel — inherits this weakness. Improper hostname verification undermines the core trust guarantee of TLS: an attacker positioned on the network path (e.g., rogue Wi-Fi, compromised router, or ISP-level adversary) could present an arbitrary valid certificate and have the client accept it as the legitimate server, opening the door to traffic interception, credential capture, or data tampering on affected connections.
What Defenders Should Do Now
- Inventory applications and services that depend on
Microsoft.Native.Quic.MsQuic.OpenSSL(via NuGet) and confirm which TLS backend they use — Schannel deployments are not impacted. - Prioritize upgrading to the patched releases: 2.6.1, 2.5.11, or 2.4.20, depending on your branch.
- Until patched, treat QUIC connections from affected builds as having reduced server-identity assurance; where feasible, avoid relying on them over untrusted networks.
- From a detection/hunting perspective, consider monitoring for anomalous certificate issuers or unexpected certificate changes on QUIC/HTTP-3 endpoints your organization controls, and review network telemetry for unexpected TLS/QUIC handshake patterns on hosts running the affected package.
- Because exploit status is reported as PoC-public, treat this as actively exploitable in principle and expedite patching over a routine cycle.
Developing Intel
This is a same-day advisory and details may evolve as the community and Microsoft provide further guidance (e.g., CVSS scoring is not yet published). For authoritative details and updates, see the original GitHub Security Advisory: GHSA-w5f4-fx9m-m4q7.