PT-2026-60592 · H2O+1 · H2O+1

CVE-2026-44433

·

Published

2026-07-16

·

Updated

2026-08-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Quicly versions prior to commit 8b178e6
Description An adversarial peer can send a STREAM frame containing a single byte at the maximum permitted offset to obtain additional flow control credit. This behavior can lead to a Denial of Service if the application allocates a receive buffer for all out-of-order data up to the largest received offset, causing memory exhaustion with very few packets. The impact depends on the application's stream concurrency control; for example, in the H2O HTTP server default settings, this can increase the maximum memory allocated per connection by approximately four times.
Recommendations Update Quicly to commit 8b178e6 or a later version.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44433
GHSA-F7QR-4P37-9GX9

Affected Products

H2O
Quicly