Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Sébastien Féry

#21231of 56,330
13Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-58086
7.5
2026-07-14
Quiche · Quiche · CVE-2026-12523
**Name of the Vulnerable Software and Affected Versions** quiche versions prior to 0.29.3 **Description** The HTTP/3 layer is susceptible to memory resource exhaustion through the use of specially crafted HTTP/3 frames. The issue occurs during the parsing of certain frame types where memory is pre-allocated based on the declared length, allowing an attacker to trigger the exhaustion without sending the full amount of declared bytes. Additionally, the software fails to correctly apply QPACK decompression limits, enabling an attacker to use crafted HEADERS frames to cause memory commitment exceeding the limits defined by `MAX FIELD SECTION SIZE` (configured via the `set max field section size()` function). **Recommendations** Upgrade to version 0.29.3 or later.
PT-2025-48796
5.5
2025-12-03
Wireshark Foundation · Wireshark · CVE-2025-13945
**Name of the Vulnerable Software and Affected Versions** Wireshark versions 4.6.0 through 4.6.1 **Description** An issue exists in the HTTP3 dissector of Wireshark that can lead to a denial of service. The vulnerability is due to a crash in the dissector when processing HTTP3 traffic. **Recommendations** Wireshark version 4.6.0: Update to a newer version to address this issue. Wireshark version 4.6.1: Update to a newer version to address this issue.