Denial of Service Vulnerability in s2n-quic by AWS
CVE-2026-94450

8.7HIGH

Key Information:

Vendor

Aws

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-94450?

The s2n-quic version 1.88.0 and earlier has a flaw in the validation of the Destination Connection ID length. This vulnerability enables an unauthenticated remote attacker to potentially crash a server endpoint, resulting in a denial of service (DoS) condition. The issue is particularly relevant for server endpoints configured to handle Retry packets, which are susceptible to being targeted by crafted UDP datagrams. To secure systems, it is crucial that users upgrade to version 1.89.0 or later.

Affected Version(s)

s2n-quic 0 <= 1.88.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.