Microsoft.Native.Quic.MsQuic.OpenSSL
Cross-platform, C implementation of the IETF QUIC protocol, exposed to C, C++, C# and Rust.
Activity
- Latest release
- 2w ago
- Total releases
- 54
- Cadence
- ~19 days
- Last 12 months
- 28
Reach
- Stars
- 4.8k
Details
- License
- MIT AND Apache-2.0
- First release
- Oct 26, 2021
| Version | Released | |
|---|---|---|
2.4.20+156138153
patch
| ||
2.6.1+156133641
patch
| ||
2.5.11+156137090
patch
| ||
2.5.11-rc+155917475
pre
| ||
2.4.20-rc+155914823
pre
| ||
2.6.0+154820802
minor
| ||
2.5.10+154567150
patch
| ||
2.4.19+154564280
patch
| ||
2.6.0-rc+154429630
pre
| ||
2.4.19-rc+154420236
pre
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.5.10-rc+154424222
pre
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.5.9+151318430
patch
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.5.9-rc2+150614355
pre
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.5.9-rc+148668048
pre
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.5.8+146488385
patch
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.5.8-rc+146300370
pre
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.4.18+144494377
patch
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.5.7+144500058
patch
1 CVE
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev | ||
2.5.7-rc2+144290866
pre
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.18-rc+144290633
pre
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.5.7-rc+138164317
pre
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.5.6+135622221
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.17+135624335
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.5.6-rc+135369822
pre
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.17-rc2+135213867
pre
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.17-rc+134531321
pre
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.16+132445597
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.5.5+132446042
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.15+130167594
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.5.4+129107507
minor
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.10+586901
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.9+584822
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.8+569855
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.7+549005
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.5+532198
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.4.3+515734
minor
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.3.6+508949
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.3.5+465110
patch
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.3.1+451282
minor
3 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev | ||
2.3.0-ci.449061
pre
2 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev | ||
2.2.3+415752
patch
3 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev | ||
2.2.2+377087
patch
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.2.0+359654
minor
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.8+348060
patch
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.7+329711
patch
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.5+308464
patch
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.3+301308
patch
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.2+300119
patch
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.1+293818
patch
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev | ||
2.1.0+284913
minor
5 CVEs
CVE-2026-62815
GHSA-92f5-vc22-8j33
Sep 08, 2026
Microsoft QUIC: Remote Code Execution Vulnerability
Critical
Network
Low
None
None
SummaryUse after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network. DetailsNew network path creations and removals triggered by incoming packets can lead to a pointer invalidation. Patches
ImpactAn unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required. Affected versions
1.8.0
Fixed in
2.4.19
2.5.10
References
Updated Sep 08, 2026 · Source: OSV.dev
CVE-2026-32179
GHSA-gvvw-8j96-8g5r
Apr 16, 2026
MsQuic has a Remote Elevation of Privilege Vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
SummaryImproper input validation in Microsoft QUIC allows an unauthorized attacker to elevate privileges over a network. DetailsImproper Input Validation Integer Underflow (Wrap or Wraparound) when decoding ACK frame. Patches
ImpactAn attacker who successfully exploited this vulnerability could gain elevated privileges. Affected versions
1.8.0
Fixed in
2.4.18
2.5.7
References Updated May 08, 2026 · Source: OSV.dev
GHSA-2x7m-gf85-3745
Mar 13, 2024
Remote Denial of Service Vulnerability in Microsoft QUIC
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. MSRC CVE Infohttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26190 Affected versions
1.8.0
Fixed in
2.1.12
2.2.7
2.3.5
References
Updated Dec 01, 2024 · Source: OSV.dev
CVE-2023-36435
GHSA-fr44-546p-7xcp
BIT-dotnet-2023-36435
BIT-dotnet-sdk-2023-36435
Oct 10, 2023
MsQuic Remote Denial of Service Vulnerability
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server will continue to leak memory until no more is available, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev
CVE-2023-38171
GHSA-xh5m-8qqp-c5x7
BIT-dotnet-2023-38171
BIT-dotnet-sdk-2023-38171
Oct 10, 2023
Remote Denial of Service Vulnerability in Microsoft.Native.Quic.MsQuic.Schannel
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactThe MsQuic server application or process will crash, resulting in a denial of service. PatchesThe following patch was made:
WorkaroundsBeyond upgrading to the patched versions, there is no other workaround. You must upgrade or disable MsQuic functionality. Affected versions
1.8.0
Fixed in
2.2.3
References
Updated Jun 03, 2024 · Source: OSV.dev |