Denial of Service Vulnerability in OpenSSL's QUIC Stream Handling
CVE-2026-42772

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-42772?

OpenSSL's management of QUIC stream fragments exhibits severe inefficiencies due to the use of a doubly-linked list for received data. When packets arrive out of order, the performance of the stream reassembly algorithm deteriorates notably, potentially leading to Denial of Service. An attacker can manipulate packet offsets to force the server into quadratic time complexity operations, causing excessive CPU usage as it processes QUIC streams. This issue allows attackers with minimal bandwidth to exhaust server resources, affecting connectivity and service availability.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.3

OpenSSL 3.6.0 < 3.6.5

OpenSSL 3.5.0 < 3.5.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Saku0512
Opal Wright (Trail of Bits)
Alexandr Nedvedicky
.