What is CVE-2026-49457?
CVE-2026-49457 is a critical vulnerability found in the `erlang_quic` library. Prior to version 1.4.4, the QUIC client failed to authenticate the server during the TLS 1.3 handshake, meaning the `CertificateVerify` signature, certificate chain, and hostname were not validated. Affected `erlang_quic` users must immediately upgrade to the latest version.
Azərbaycanca: CVE-2026-49457, `erlang_quic` kitabxanasında aşkar edilmiş kritik zəiflikdir. 1.4.4 versiyasından əvvəlki versiyalarda, QUIC müştərisi TLS 1.3 handshake prosesi zamanı serveri autentifikasiya etmir; `CertificateVerify` imzası, sertifikat zənciri yoxlanılmır və hostname sertifikatla müqayisə edilmir. Təsirə məruz qalan `erlang_quic` istifadəçiləri dərhal ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of `erlang_quic` are affected by CVE-2026-49457?
All versions of `erlang_quic` prior to version 1.4.4 are affected by this vulnerability.
Which steps of the TLS 1.3 handshake are not validated due to CVE-2026-49457 in the QUIC client?
The vulnerability causes the `CertificateVerify` signature, certificate chain, and hostname comparison against the certificate to not be validated.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.