THREAT OPS › Threat News › [NVD] CVE-2026-49457 (CRITICAL 9.1) — erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared agai
[NVD] CVE-2026-49457 (CRITICAL 9.1) — erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared agai
CVE-2026-49457 CVSS: 9.1 CRITICAL Published: 2026-08-14T19:17:18.707
erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so `verify` was effectively a
Indicators of compromise
- CVE-2026-49457cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49457