Openssl · Openssl · CVE-2026-63075
**Name of the Vulnerable Software and Affected Versions**
OpenSSL (affected versions not specified)
**Description**
When processing QUIC traffic, the QUIC stack may retain metadata for ACK-only packets for the entire duration of a connection if a peer repeatedly sends ack-eliciting packets without acknowledging the ACK-only responses. A remote peer that completes a QUIC handshake can exploit this by sending numerous PING frames to force the generation of ACK-only packets while withholding acknowledgments for ack-eliciting data. This behavior causes connection-scoped memory growth, which can lead to a Denial of Service through memory exhaustion, particularly during sustained traffic or across many concurrent QUIC connections.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.