PT-2026-58086 · Quiche · Quiche

·

CVE-2026-12523

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions quiche versions prior to 0.29.3
Description The HTTP/3 layer is susceptible to memory resource exhaustion through the use of specially crafted HTTP/3 frames. The issue occurs during the parsing of certain frame types where memory is pre-allocated based on the declared length, allowing an attacker to trigger the exhaustion without sending the full amount of declared bytes. Additionally, the software fails to correctly apply QPACK decompression limits, enabling an attacker to use crafted HEADERS frames to cause memory commitment exceeding the limits defined by MAX FIELD SECTION SIZE (configured via the set max field section size() function).
Recommendations Upgrade to version 0.29.3 or later.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12523
GHSA-4FGF-9XRR-88GF

Affected Products

Quiche