PT-2026-97044 · S2N-Quic · S2N-Quic
CVE-2026-94450
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
s2n-quic versions prior to 1.89.0
Description
Improper validation of the Destination Connection ID length allows an unauthenticated remote user to cause a denial of service by shutting down a server endpoint using a single crafted UDP datagram. This issue specifically affects server endpoints configured to send Retry packets.
Recommendations
Upgrade to version 1.89.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
S2N-Quic