Denial of Service Vulnerability in OpenSSL QUIC Implementation
CVE-2026-63075
Currently unrated
What is CVE-2026-63075?
The OpenSSL QUIC stack has a vulnerability that allows a remote peer to exploit ACK-only packets. When a malicious peer establishes a QUIC connection and sends numerous PING frames without acknowledging ACK-only responses, it can cause the OpenSSL implementation to retain excessive metadata. This uncontrolled retention may lead to connection-scoped memory growth, ultimately resulting in Denial of Service through memory exhaustion. The issue stems from the lack of proper limits during the handling of these packets, making it essential to implement a fix to address the storage of ACK-only packet metadata.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.2
OpenSSL 3.6.0 < 3.6.4
OpenSSL 3.5.0 < 3.5.8