Resource Depletion Vulnerability in OpenSSL QUIC Stack
CVE-2026-84784
Currently unrated
What is CVE-2026-84784?
A vulnerability exists in the OpenSSL QUIC stack that allows a malicious remote peer to flood the local stack with NEW_CONNECTION_ID frames. This manipulation circumvents limits on how many connection IDs can be processed, potentially leading to excessive resource allocation, specifically around 400MB. The issue arises from the flawed logic in handling RETIRE_CONNECTION_ID frames, which could be exploited if the remote peer withholds ACKs, thereby increasing backlog on the local QUIC stack. Correcting this logic is essential to ensure stable resource management and prevent unwanted allocation spikes.
Affected Version(s)
OpenSSL 4.0.0 < 4.0.3
OpenSSL 3.6.0 < 3.6.5
OpenSSL 3.5.0 < 3.5.9