PT-2026-102648 · Openssl · Openssl

·

CVE-2026-35191

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions OpenSSL (affected versions not specified)
Description The OpenSSL QUIC server, when configured to skip address validation, incorrectly calculates the unvalidated credit limit. When processing a datagram containing multiple QUIC packets, the server adds the total length of the entire datagram to the credit limit for every individual packet contained within it. This behavior allows a remote attacker to spoof packets and trick the server into believing more data was received than actually occurred, violating the RFC 9000 amplification limit of three times the received data. Consequently, a remote attacker could leverage the server to amplify a Distributed Denial of Service (DDoS) attack.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35191
USN-8847-1

Affected Products

Openssl