quic
Pure Erlang QUIC implementation (RFC 9000)
Activity
- Latest release
- 1w ago
- Total releases
- 39
- Cadence
- ~daily
- Last 12 months
- 39
Reach
- Downloads
- 517.4k
Details
- License
- Apache-2.0
- First release
- Feb 17, 2026
| Version | Released | |
|---|---|---|
1.8.2
patch
| ||
1.8.1
patch
| ||
1.8.0
minor
| ||
1.7.1
patch
| ||
1.7.0
minor
| ||
1.6.5
patch
| ||
1.6.4
patch
| ||
1.6.3
patch
| ||
1.6.2
patch
| ||
1.6.1
patch
| ||
1.6.0
minor
| ||
1.5.0
minor
| ||
1.4.5
patch
| ||
1.4.4
patch
| ||
1.4.3
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.4.2
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.4.1
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.3.3
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.3.2
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.3.1
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.3.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.2.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.1.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.0.2
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.0.1
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
1.0.0
major
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.10.2
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.10.1
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.1
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.5
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.1
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.1
patch
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev | ||
0.5.0
initial
1 CVE
CVE-2026-49457
GHSA-2r8v-p65x-3663
Jul 01, 2026
QUIC has Broken TLS verification
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
None
ImpactThe QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so PatchesFixed in 1.4.4. The client now verifies the CertificateVerify signature, validates the certificate chain against the trust store ( WorkaroundsNone before 1.4.4. CreditReported by benmmurphy. Affected versions
0.10.0
0.10.1
0.10.2
0.11.0
0.5.0
0.5.1
0.6.0
0.6.1
0.6.5
0.7.0
0.7.1
0.9.0
+ 13 more Show less
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.3.1
1.3.2
1.3.3
1.4.0
1.4.1
1.4.2
1.4.3
Fixed in
1.4.4
References Updated Jul 01, 2026 · Source: OSV.dev |