Executive brief
The erlang_quic library, which provides QUIC and HTTP/3 protocol support, failed to properly verify security certificates during encrypted connections. This allows an attacker positioned on the network to impersonate legitimate servers and intercept or modify sensitive data. Organizations using this library for secure communications are at risk of data exposure and loss of connection integrity.
Technical details
The erlang_quic client suffered from improper certificate validation (CWE-295) and improper validation of certificate hostnames (CWE-297) during TLS 1.3 handshakes. Specifically, the CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate. A network-positioned attacker (Man-in-the-Middle) could present any certificate to impersonate a server, compromising confidentiality and integrity. This affected both QUIC and HTTP/3 clients, though handshakes using Pre-Shared Keys (PSK) for session resumption were not impacted. The issue is fixed in version 1.4.4, which enables verification by default.
Affected products
- benoitc/erlang_quic quic <= 1.4.3
Timeline
- 2026-05-27: disclosed: Initial report to developer
- 2026-07-01: advisory: GitHub Advisory published
- 2026-07-01: patched: Fixed in version 1.4.4