Netty QUIC codec is a QUIC codec for netty which makes use of quiche. An issue was discovered in the codec. A hash collision vulnerability (in the hash map used to manage connections) allows remote attackers to cause a considerable CPU load on the server (a Hash DoS attack) by initiating connections with colliding Source Connection IDs (SCIDs). This vulnerability is fixed in 0.0.71.Final.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/29xxx/CVE-2025-29908.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-407"
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"24245573678652468727239713428523539110",
"224098237857714628598687956596141119693",
"252002819166747902197133671509976043134",
"92187415981804453108270526594126188381",
"338311506484926879584335745523936720407",
"169736296601294300709449375701589905759",
"279353158771539648245571498047756752840",
"136034302237178359550967443199489966698",
"184158311516653853694192594186558669014",
"228091686509308466998442404641394167967"
]
},
"signature_version": "v1",
"source": "https://github.com/netty/netty-incubator-codec-quic/commit/e059bd9b78723f8b035e0c547e42ce263f03461c",
"signature_type": "Line",
"target": {
"file": "codec-classes-quic/src/main/java/io/netty/incubator/codec/quic/QuicheQuicCodec.java"
},
"id": "CVE-2025-29908-5e32a9c4",
"deprecated": false
}
]
"2026-07-22T04:01:43Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-29908.json"