OpenSSL QUIC Stack Connection Flow Control Insufficiency
CVE-2026-75804

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-75804?

The OpenSSL QUIC stack demonstrates a vulnerability due to its failure to enforce connection-level flow control for streams. While it correctly manages stream-level limits, it inadequately restricts the amount of memory that can be allocated at the connection level. This oversight can be exploited by a remote peer capable of sending multiple streams that remain within stream-level limits, potentially forcing the QUIC implementation to allocate significant amounts of memory—up to 100MB per connection—leading to resource exhaustion. This vulnerability poses a risk as it allows attackers to bypass flow control measures by manipulating the communication protocol's limitations.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.3

OpenSSL 3.6.0 < 3.6.5

OpenSSL 3.5.0 < 3.5.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moltenbit
Bhabani Sankar Das
Saiyowa Security Team
Alexandr Nedvedicky
.