PT-2026-60592 · H2O+1 · H2O+1
CVE-2026-44433
·
Published
2026-07-16
·
Updated
2026-08-06
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Quicly versions prior to commit 8b178e6
Description
An adversarial peer can send a STREAM frame containing a single byte at the maximum permitted offset to obtain additional flow control credit. This behavior can lead to a Denial of Service if the application allocates a receive buffer for all out-of-order data up to the largest received offset, causing memory exhaustion with very few packets. The impact depends on the application's stream concurrency control; for example, in the H2O HTTP server default settings, this can increase the maximum memory allocated per connection by approximately four times.
Recommendations
Update Quicly to commit 8b178e6 or a later version.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
H2O
Quicly