OpenSSL QUIC Server Vulnerability in Multiple Versions
CVE-2026-35191
Currently unrated
What is CVE-2026-35191?
The OpenSSL QUIC server, when not configured to perform address validation, is susceptible to manipulation by remote attackers. This vulnerability allows attackers to exploit the server's credit computation by counting incoming packets multiple times. If address validation is turned off, the server may miscalculate the traffic it receives, potentially exceeding the amplification limit defined by RFC 9000. This behavior exposes the server to DDoS amplification attacks, since an attacker can spoof packets to amplify their traffic through the server, resulting in increased loads on targeted systems.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9