PT-2026-60601 · Quicly · Quicly

CVE-2026-44435

·

Published

2026-07-16

·

Updated

2026-08-06

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Quicly versions prior to commit 937d0e9
Description An assertion failure occurs when the total number of valid handshake messages received over a CRYPTO stream of a single packet number space exceeds 32KB. This leads to a Denial of Service, which is a condition where the system becomes unavailable to its intended users.
Recommendations Update to the version containing commit 937d0e9.

Exploit

Fix

DoS

Assertion Failure

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44435
GHSA-2CW9-5673-73GV

Affected Products

Quicly