Resource Depletion Vulnerability in OpenSSL QUIC Stack
CVE-2026-84784

Currently unrated

Key Information:

Vendor

OpenSSL

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-84784?

A vulnerability exists in the OpenSSL QUIC stack that allows a malicious remote peer to flood the local stack with NEW_CONNECTION_ID frames. This manipulation circumvents limits on how many connection IDs can be processed, potentially leading to excessive resource allocation, specifically around 400MB. The issue arises from the flawed logic in handling RETIRE_CONNECTION_ID frames, which could be exploited if the remote peer withholds ACKs, thereby increasing backlog on the local QUIC stack. Correcting this logic is essential to ensure stable resource management and prevent unwanted allocation spikes.

Affected Version(s)

OpenSSL 4.0.0 < 4.0.3

OpenSSL 3.6.0 < 3.6.5

OpenSSL 3.5.0 < 3.5.9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bhabani Sankar Das
Alexandr Nedvedicky
.