GHSA-6w86-wgwq-rgq8

Suggest an improvement
Source
https://github.com/advisories/GHSA-6w86-wgwq-rgq8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6w86-wgwq-rgq8/GHSA-6w86-wgwq-rgq8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6w86-wgwq-rgq8
Published
2026-03-04T20:16:26Z
Modified
2026-03-04T20:31:17Z
Severity
  • 5.1 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
neqo-qpack has iInteger overflow in qpack dynamic table indexing
Details

Summary

An unsanitized qpack index can lead to an integer overflow, panicing in debug mode, accessing the wrong or no dynamic table entry in release mode.

What does this mean for Firefox? Firefox runs Neqo in release mode. A malicious remote can cause its own QUIC connection to fail to use qpack, i.e. compression, or enter an inconsistent state. The remote can not crash Firefox, nor affect other QUIC connections.

Details

See fuzz report in https://github.com/mozilla/neqo/issues/3406.

PoC

See test in pull request.

Impact

All Firefox users. Though vulnerability likely scoped to same connection, i.e. low impact.

Database specific
{
    "cwe_ids":  [
        "CWE-190"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-04T20:16:26Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / neqo-qpack

Package

Name
neqo-qpack
View open source insights on deps.dev
Purl
pkg:cargo/neqo-qpack

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.22.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6w86-wgwq-rgq8/GHSA-6w86-wgwq-rgq8.json"