GHSA-92f5-vc22-8j33

Suggest an improvement
Source
https://github.com/advisories/GHSA-92f5-vc22-8j33
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-92f5-vc22-8j33/GHSA-92f5-vc22-8j33.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-92f5-vc22-8j33
Aliases
  • CVE-2026-62815
Published
2026-09-08T20:27:02Z
Modified
2026-09-08T20:45:04Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Microsoft QUIC: Remote Code Execution Vulnerability
Details

Summary

Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

Details

New network path creations and removals triggered by incoming packets can lead to a pointer invalidation.

Patches

Impact

An unauthenticated attacker could exploit this vulnerability by sending a specially crafted packet to an affected service over the network. Successful exploitation could allow the attacker to execute code on the target system. No authentication or user interaction is required.

Database specific
{
    "cwe_ids": [
        "CWE-416"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-08T20:27:02Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

NuGet
Microsoft.Native.Quic.MsQuic.OpenSSL

Package

Name
Microsoft.Native.Quic.MsQuic.OpenSSL
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.Native.Quic.MsQuic.OpenSSL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.5.3
Fixed
2.5.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-92f5-vc22-8j33/GHSA-92f5-vc22-8j33.json"
Microsoft.Native.Quic.MsQuic.Schannel

Package

Name
Microsoft.Native.Quic.MsQuic.Schannel
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.Native.Quic.MsQuic.Schannel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.5.3
Fixed
2.5.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-92f5-vc22-8j33/GHSA-92f5-vc22-8j33.json"
Microsoft.Native.Quic.MsQuic.OpenSSL

Package

Name
Microsoft.Native.Quic.MsQuic.OpenSSL
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.Native.Quic.MsQuic.OpenSSL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.19

Affected versions

1.*
1.8.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-92f5-vc22-8j33/GHSA-92f5-vc22-8j33.json"
Microsoft.Native.Quic.MsQuic.Schannel

Package

Name
Microsoft.Native.Quic.MsQuic.Schannel
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.Native.Quic.MsQuic.Schannel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.19

Affected versions

1.*
1.8.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-92f5-vc22-8j33/GHSA-92f5-vc22-8j33.json"