Junglewise Threat Intelligence

CVE-2026-50010: Netty disabled TLS hostname verification in netty-handler

CVE-2026-50010 · Severity: high · CVSS 7.5 · Published 2026-06-12

Vendors: Netty.

Executive brief

Netty is a popular networking framework used by many Java applications to handle internet communications. A flaw in how it handles security certificates means that even when developers enable 'hostname verification' (a check to ensure a website is who it says it is), the check may be silently skipped. This could allow an attacker to intercept or eavesdrop on encrypted traffic between a client and a server without being detected.

Technical details

The vulnerability exists in SimpleTrustManagerFactory.engineGetTrustManagers() and related code paths within the netty-handler package. When a user provides a plain X509TrustManager, Netty wraps it in an X509TrustManagerWrapper. This wrapper extends X509ExtendedTrustManager but incorrectly implements the 3-argument checkServerTrusted method by discarding the SSLEngine parameter and delegating to the 2-argument version. Because the resulting object is technically an instance of X509ExtendedTrustManager, subsequent security layers (like SunJSSE or Netty's OpenSslX509TrustManagerWrapper) fail to apply necessary endpoint identification logic. This results in a complete bypass of hostname verification for clients configured with SslContextBuilder.forClient().trustManager(...). The issue is resolved in versions 4.1.135.Final and 4.2.15.Final.

Affected products

  • Netty netty-handler >= 4.2.0.Final, < 4.2.15.Final
  • Netty netty-handler <= 4.1.134.Final

Timeline

  • 2026-06-02: patched: Release of 4.1.135.Final and 4.2.15.Final
  • 2026-06-05: disclosed: Initial advisory publication
  • 2026-06-12: advisory: NVD publication
  • 2026-06-15: advisory: GitHub Advisory reviewed and updated

References