{
  "id": "CVE-2026-50010",
  "url": "https://spydr.io/cve/CVE-2026-50010",
  "published": "2026-06-12T16:16:31.180Z",
  "modified": "2026-09-18T13:18:31.640Z",
  "score": 7.5,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "score_source": "github.com",
  "epss": 0.00721,
  "epss_percentile": 0.52352,
  "exploited": false,
  "kev": null,
  "ssvc_exploitation": "none",
  "vendors": [
    "netty",
    "Red Hat"
  ],
  "products": [
    "netty",
    "Red Hat Cryostat 4 on RHEL 9",
    "Red Hat AMQ Broker 7.13.6",
    "Red Hat AMQ Broker 7.14.1",
    "Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.2.SP1",
    "Red Hat build of Apache Camel 4.18.1.P1 for Spring Boot 3.5.16",
    "Red Hat build of Quarkus 3.27.4.SP1",
    "Red Hat build of Quarkus 3.33.2.SP1",
    "Red Hat Data Grid 8.6.2",
    "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7",
    "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8",
    "Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9",
    "Red Hat JBoss Enterprise Application Platform 8.1",
    "Red Hat JBoss Enterprise Application Platform 8.1.7.GA",
    "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10",
    "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8",
    "Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9",
    "Red Hat Streams for Apache Kafka 2.9.4",
    "Red Hat Offline Knowledge Portal 1.2.12",
    "Red Hat OpenShift AI 2.25"
  ],
  "cwes": [
    "CWE-347"
  ],
  "description": "Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SimpleTrustManagerFactory.engineGetTrustManagers() and related paths wrap any user-supplied plain X509TrustManager in X509TrustManagerWrapper, which extends X509ExtendedTrustManager but implements the 3-arg checkServerTrusted(chain, authType, SSLEngine) by discarding the SSLEngine and calling the 2-arg delegate. Because the object now IS an X509ExtendedTrustManager, neither SunJSSE's internal AbstractTrustManagerWrapper nor Netty's own OpenSslX509TrustManagerWrapper will re-wrap it to add endpoint-identification. Consequently, even though Netty 4.2 sets endpointIdentificationAlgorithm=\"HTTPS\" by default, a client built with `SslContextBuilder.forClient().trustManager(somePlainX509TrustManager)` performs no hostname verification at all. Versions 4.1.135.Final and 4.2.15.Final patch the issue.",
  "status": "Modified",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://github.com/netty/netty/releases/tag/netty-4.1.135.Final",
      "tags": [
        "Release Notes"
      ]
    },
    {
      "url": "https://github.com/netty/netty/releases/tag/netty-4.2.15.Final",
      "tags": [
        "Release Notes"
      ]
    },
    {
      "url": "https://github.com/netty/netty/security/advisories/GHSA-c653-97m9-rcg9",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26017",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26018",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:26586",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:28573",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:34608",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:37390",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:41951",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:48151",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:49700",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:49701",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:50085",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:53644",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:53645",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:53646",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:62260",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:65126",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:66488",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2026:66545",
      "tags": []
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2026-50010",
      "tags": []
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2488429",
      "tags": []
    },
    {
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50010.json",
      "tags": []
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-50010",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
