OpenSSL QUIC Stack Connection Flow Control Insufficiency
CVE-2026-75804
Currently unrated
What is CVE-2026-75804?
The OpenSSL QUIC stack demonstrates a vulnerability due to its failure to enforce connection-level flow control for streams. While it correctly manages stream-level limits, it inadequately restricts the amount of memory that can be allocated at the connection level. This oversight can be exploited by a remote peer capable of sending multiple streams that remain within stream-level limits, potentially forcing the QUIC implementation to allocate significant amounts of memory—up to 100MB per connection—leading to resource exhaustion. This vulnerability poses a risk as it allows attackers to bypass flow control measures by manipulating the communication protocol's limitations.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9