PT-2026-60600 · H2O+1 · H2O+1

CVE-2026-44434

·

Published

2026-07-16

·

Updated

2026-08-06

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Quicly versions prior to commit dccf5d4
Description Quicly, an IETF QUIC protocol implementation used primarily in the H2O HTTP server, is susceptible to stateless reset injection due to insufficient packet entry validation. While the QUIC protocol uses secret patterns to prevent packet injection attacks after the handshake, Quicly failed to verify which of its four internal slots for these patterns contained valid entries. Because these slots are zero-initialized, any slot not explicitly filled by the peer was treated as containing an all-zero pattern. This allows an on-path attacker to trigger a stateless reset and terminate QUIC connections.
Recommendations Update Quicly to the version containing commit dccf5d4.

Exploit

Fix

Improper Initialization

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44434
GHSA-899F-49JQ-PFH8

Affected Products

H2O
Quicly