PT-2026-60600 · H2O+1 · H2O+1
CVE-2026-44434
·
Published
2026-07-16
·
Updated
2026-08-06
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Quicly versions prior to commit dccf5d4
Description
Quicly, an IETF QUIC protocol implementation used primarily in the H2O HTTP server, is susceptible to stateless reset injection due to insufficient packet entry validation. While the QUIC protocol uses secret patterns to prevent packet injection attacks after the handshake, Quicly failed to verify which of its four internal slots for these patterns contained valid entries. Because these slots are zero-initialized, any slot not explicitly filled by the peer was treated as containing an all-zero pattern. This allows an on-path attacker to trigger a stateless reset and terminate QUIC connections.
Recommendations
Update Quicly to the version containing commit dccf5d4.
Exploit
Fix
Improper Initialization
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
H2O
Quicly