quiche
Activity
- Latest release
- 2mo ago
- Total releases
- 60
- Cadence
- ~25 days
- Last 12 months
- 12
Details
- License
- BSD-2-Clause
- First release
- Jan 24, 2019
| Version | Released | |
|---|---|---|
0.29.3
unknown
|
0.29.3
unknown
Dependencies (24)
+ 16 more |
|
0.29.2
unknown
|
0.29.2
unknown
Dependencies (24)
+ 16 more |
|
0.29.1
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.29.1
unknown
Dependencies (24)
+ 16 more |
|
0.29.0
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.29.0
unknown
Dependencies (24)
+ 16 more |
|
0.28.0
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.28.0
unknown
Dependencies (25)
+ 17 more |
|
0.27.0
unknown
yanked
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.27.0
unknown
yanked
Dependencies (25)
+ 17 more |
|
0.26.1
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.26.1
unknown
Dependencies (24)
+ 16 more |
|
0.26.0
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.26.0
unknown
Dependencies (24)
+ 16 more |
|
0.25.0
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.25.0
unknown
Dependencies (22)
+ 14 more |
|
0.24.9
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.24.9
unknown
Dependencies (21)
+ 13 more |
|
0.24.8
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.24.8
unknown
Dependencies (21)
+ 13 more |
|
0.24.7
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.24.7
unknown
Dependencies (21)
+ 13 more |
|
0.24.6
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.24.6
unknown
Dependencies (22)
+ 14 more |
|
0.24.5
unknown
1 CVE
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev |
0.24.5
unknown
Dependencies (22)
+ 14 more |
|
0.24.4
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.24.4
unknown
Dependencies (22)
+ 14 more |
|
0.24.3
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.24.3
unknown
Dependencies (22)
+ 14 more |
|
0.24.2
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.24.2
unknown
Dependencies (22)
+ 14 more |
|
0.24.1
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.24.1
unknown
Dependencies (22)
+ 14 more |
|
0.24.0
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.24.0
unknown
Dependencies (22)
+ 14 more |
|
0.23.7
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.23.7
unknown
Dependencies (22)
+ 14 more |
|
0.23.6
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.23.6
unknown
Dependencies (21)
+ 13 more |
|
0.23.5
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.23.5
unknown
Dependencies (19)
+ 11 more |
|
0.23.4
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.23.4
unknown
Dependencies (19)
+ 11 more |
|
0.23.3
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.23.3
unknown
Dependencies (19)
+ 11 more |
|
0.23.2
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.23.2
unknown
Dependencies (19)
+ 11 more |
|
0.23.1
unknown
yanked
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.23.1
unknown
yanked
Dependencies (19)
+ 11 more |
|
0.23.0
unknown
yanked
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.23.0
unknown
yanked
Dependencies (19)
+ 11 more |
|
0.22.0
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.22.0
unknown
Dependencies (20)
+ 12 more |
|
0.21.0
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.21.0
unknown
Dependencies (19)
+ 11 more |
|
0.20.1
unknown
2 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.20.1
unknown
Dependencies (18)
+ 10 more |
|
0.19.2
unknown
1 CVE
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev |
0.19.2
unknown
Dependencies (18)
+ 10 more |
|
0.20.0
unknown
4 CVEs
CVE-2026-11941
GHSA-mh64-ph39-mrc9
Jun 19, 2026
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
5.6
/ 10
Medium
Network
High
None
None
Unchanged
Low
Low
Low
ImpactCloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. quiche 0.29.2 is the earliest version containing the fix for this issue. Fixed in
0.29.2
References Updated Jun 19, 2026 · Source: OSV.dev
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.20.0
unknown
Dependencies (18)
+ 10 more |
|
0.19.1
unknown
3 CVEs
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.19.1
unknown
Dependencies (18)
+ 10 more |
|
0.19.0
unknown
4 CVEs
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-6193
GHSA-w3vp-jw9m-f9pm
Dec 13, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Impactquiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received, leading to storage of path validation data in an unbounded queue. PatchesQuiche versions greater than 0.19.0 address this problem. ReferencesFixed in
0.19.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.19.0
unknown
Dependencies (18)
+ 10 more |
|
0.18.0
unknown
4 CVEs
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-6193
GHSA-w3vp-jw9m-f9pm
Dec 13, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Impactquiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received, leading to storage of path validation data in an unbounded queue. PatchesQuiche versions greater than 0.19.0 address this problem. ReferencesFixed in
0.19.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.18.0
unknown
Dependencies (18)
+ 10 more |
|
0.17.2
unknown
4 CVEs
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-6193
GHSA-w3vp-jw9m-f9pm
Dec 13, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Impactquiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received, leading to storage of path validation data in an unbounded queue. PatchesQuiche versions greater than 0.19.0 address this problem. ReferencesFixed in
0.19.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.17.2
unknown
Dependencies (16)
+ 8 more |
|
0.17.1
unknown
4 CVEs
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-6193
GHSA-w3vp-jw9m-f9pm
Dec 13, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Impactquiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received, leading to storage of path validation data in an unbounded queue. PatchesQuiche versions greater than 0.19.0 address this problem. ReferencesFixed in
0.19.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.17.1
unknown
Dependencies (16)
+ 8 more |
|
0.17.0
unknown
yanked
4 CVEs
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-6193
GHSA-w3vp-jw9m-f9pm
Dec 13, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Impactquiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received, leading to storage of path validation data in an unbounded queue. PatchesQuiche versions greater than 0.19.0 address this problem. ReferencesFixed in
0.19.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.17.0
unknown
yanked
Dependencies (16)
+ 8 more |
|
0.16.0
unknown
4 CVEs
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-6193
GHSA-w3vp-jw9m-f9pm
Dec 13, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Impactquiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received, leading to storage of path validation data in an unbounded queue. PatchesQuiche versions greater than 0.19.0 address this problem. ReferencesFixed in
0.19.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.16.0
unknown
Dependencies (15)
+ 7 more |
|
0.15.0
unknown
4 CVEs
CVE-2025-7054
GHSA-m3hh-f9gh-74c2
Aug 07, 2025
quiche connection ID retirement can trigger an infinite loop
High
Network
Low
None
None
ImpactCloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000. Once the QUIC handshake completes, a local endpoint is responsible for issuing and retiring Connection IDs that are used by the remote peer to populate the Destination Connection ID field in packets sent from remote to local. Each Connection ID has a sequence number to ensure synchronization between peers An unauthenticated remote attacker can exploit this vulnerability by first completing a handshake and then sending a specially-crafted set of frames that trigger a connection ID retirement in the victim. When the victim attempts to send a packet containing RETIRE_CONNECTION_ID frames, Section 19.16 of RFC 9000 requires that the sequence number of the retired connection ID must not be the same as the sequence number of the connection ID used by the packet. In other words, a packet cannot contain a frame that retires itself. In scenarios such as path migration, it is possible for there to be multiple active paths with different active connection IDs that could be used to retire each other. The exploit triggered an unintentional behaviour of a quiche design feature that supports retirement across paths while maintaining full connection ID synchronization, leading to an infinite loop. Patchesquiche 0.24.5 is the earliest version containing the fix for the issue Fixed in
0.24.5
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2023-6193
GHSA-w3vp-jw9m-f9pm
Dec 13, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Impactquiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by sending a PATH_RESPONSE. An unauthenticated remote attacker can exploit the vulnerability by sending PATH_CHALLENGE frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that PATH_RESPONSE frames can only be sent at the slower rate than they are received, leading to storage of path validation data in an unbounded queue. PatchesQuiche versions greater than 0.19.0 address this problem. ReferencesFixed in
0.19.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.15.0
unknown
Dependencies (15)
+ 7 more |
|
0.14.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.14.0
unknown
Dependencies (14)
+ 6 more |
|
0.13.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.13.0
unknown
Dependencies (14)
+ 6 more |
|
0.12.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.12.0
unknown
Dependencies (11)
+ 3 more |
|
0.11.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.11.0
unknown
Dependencies (11)
+ 3 more |
|
0.10.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.10.0
unknown
Dependencies (11)
+ 3 more |
|
0.9.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.9.0
unknown
Dependencies (11)
+ 3 more |
|
0.8.1
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.1
unknown
Dependencies (11)
+ 3 more |
|
0.8.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.8.0
unknown
Dependencies (11)
+ 3 more |
|
0.7.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.7.0
unknown
Dependencies (11)
+ 3 more |
|
0.6.0
unknown
2 CVEs
CVE-2024-1765
GHSA-78wx-jg4j-5j6g
Mar 13, 2024
quiche vulnerable to unlimited resource allocation by QUIC CRYPTO frames flooding
5.9
/ 10
Medium
Network
High
None
None
Unchanged
None
None
High
ImpactCloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly sending an unlimited number of 1-RTT CRYPTO frames after previously completing the QUIC handshake. Exploitation was possible for the duration of the connection which could be extended by the attacker. PatchesQuiche 0.19.2 and 0.20.1 are the earliest versions containing the fix for this issue. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev
CVE-2024-1410
GHSA-xhg9-xwch-vr7x
Mar 13, 2024
quiche vulnerable to unbounded storage of information related to connection ID retirement
3.7
/ 10
Low
Network
High
None
None
Unchanged
None
None
Low
ImpactCloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1. Endpoints declare the number of active connection IDs they are willing to support using the active_connection_id_limit transport parameter. The peer can create new IDs using a NEW_CONNECTION_ID frame but must stay within the active ID limit. This is done by retirement of old IDs, the endpoint sends NEW_CONNECTION_ID includes a value in the retire_prior_to field, which elicits a RETIRE_CONNECTION_ID frame as confirmation. An unauthenticated remote attacker can exploit the vulnerability by sending NEW_CONNECTION_ID frames and manipulating the connection (e.g. by restricting the peer's congestion window size) so that RETIRE_CONNECTION_ID frames can only be sent at a slower rate than they are received, leading to storage of information related to connection IDs in an unbounded queue. PatchesQuiche versions 0.19.2 and 0.20.1 are the earliest to address this problem. There is no workaround for affected versions. Fixed in
0.19.2
0.20.1
References
Updated Jul 08, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (10)
+ 2 more |