← Blog · · df00tech

MsQuic OpenSSL/QuicTLS Backend: Improper Certificate Validation Enables MITM (CVE-2026-105794)

breaking ghsa nuget CVE-2026-105794

What Happened

Microsoft disclosed a GitHub Security Advisory (GHSA-w5f4-fx9m-m4q7, CVE-2026-105794) affecting Microsoft.Native.Quic.MsQuic.OpenSSL. According to the advisory, MsQuic improperly verifies the TLS hostname when using the OpenSSL or QuicTLS backends. The Schannel backend is explicitly called out as not affected. The flaw allows an on-path attacker to spoof a server identity by presenting a certificate that does not match the intended target hostname, enabling a man-in-the-middle (MITM) attack against QUIC connections. Fixes are available in versions 2.6.1, 2.5.11, and 2.4.20. Exploit status is listed as PoC-public; no CVSS score has been published yet.

Why It Matters

MsQuic is Microsoft's QUIC implementation and is embedded in products and libraries that negotiate QUIC/HTTP-3 connections. Any consumer that builds with the OpenSSL or QuicTLS TLS backend — rather than Schannel — inherits this weakness. Improper hostname verification undermines the core trust guarantee of TLS: an attacker positioned on the network path (e.g., rogue Wi-Fi, compromised router, or ISP-level adversary) could present an arbitrary valid certificate and have the client accept it as the legitimate server, opening the door to traffic interception, credential capture, or data tampering on affected connections.

What Defenders Should Do Now

  • Inventory applications and services that depend on Microsoft.Native.Quic.MsQuic.OpenSSL (via NuGet) and confirm which TLS backend they use — Schannel deployments are not impacted.
  • Prioritize upgrading to the patched releases: 2.6.1, 2.5.11, or 2.4.20, depending on your branch.
  • Until patched, treat QUIC connections from affected builds as having reduced server-identity assurance; where feasible, avoid relying on them over untrusted networks.
  • From a detection/hunting perspective, consider monitoring for anomalous certificate issuers or unexpected certificate changes on QUIC/HTTP-3 endpoints your organization controls, and review network telemetry for unexpected TLS/QUIC handshake patterns on hosts running the affected package.
  • Because exploit status is reported as PoC-public, treat this as actively exploitable in principle and expedite patching over a routine cycle.

Developing Intel

This is a same-day advisory and details may evolve as the community and Microsoft provide further guidance (e.g., CVSS scoring is not yet published). For authoritative details and updates, see the original GitHub Security Advisory: GHSA-w5f4-fx9m-m4q7.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.