THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-49457 (CRITICAL 9.1) — erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared agai

[NVD] CVE-2026-49457 (CRITICAL 9.1) — erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared agai

lownvdPublished 2026-08-14

CVE-2026-49457 CVSS: 9.1 CRITICAL Published: 2026-08-14T19:17:18.707

erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared against the certificate, so `verify` was effectively a

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-49457