LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-44435

h2o · quicly

Published
CVSS7.5
Severityhigh
WeaknessCWE-400
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised when the total number of valid handshake messages received over a CRYPTO stream of a single packet number space exceeds 32KB, causing a Denial of Service. This issue has been fixed by commit 937d0e9.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44435

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44435.