CVE-2026-44435

Source
https://cve.org/CVERecord?id=CVE-2026-44435
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44435.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-44435
Aliases
  • GHSA-2cw9-5673-73gv
Published
2026-07-16T22:39:50.873Z
Modified
2026-07-19T03:31:07.467308318Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB
Details

Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised when the total number of valid handshake messages received over a CRYPTO stream of a single packet number space exceeds 32KB, causing a Denial of Service. This issue has been fixed by commit 937d0e9.

Database specific
{
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "937d0e9"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44435.json",
    "cwe_ids": [
        "CWE-400",
        "CWE-617"
    ]
}
References

Affected packages

Git / github.com/h2o/quicly

Affected ranges

Type
GIT
Repo
https://github.com/h2o/quicly
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-44435.json"