Issue summary: Remote peer may exhaust heap memory of the QUIC
server or client by flooding it with packets containing PATH_CHALLENGE
frames.
Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.
A remote peer may exhaust heap memory by flooding the local
QUIC stack with PATH_CHALLENGE frames. The local QUIC stack
allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives.
The allocated PATH_RESPONSE frame gets freed only when the remote
peer acknowledges reception of the PATH_RESPONSE frame which will
not be done by a malicious peer.
The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.
{
"license": "CC-BY-4.0",
"sources": [
{
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34183",
"database_specific": {
"status": "Analyzed"
},
"modified": "2026-07-23T08:10:00.137Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-34183",
"imported": "2026-08-03T18:18:15.519Z",
"id": "CVE-2026-34183",
"published": "2026-06-09T17:17:05Z"
},
{
"imported": "2026-08-03T18:19:52.623Z",
"html_url": "https://github.com/advisories/GHSA-f5vx-f6jp-89j6",
"modified": "2026-06-10T18:31:41Z",
"url": "https://api.github.com/advisories/GHSA-f5vx-f6jp-89j6",
"id": "GHSA-f5vx-f6jp-89j6",
"published": "2026-06-09T18:30:41Z"
},
{
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35479",
"imported": "2026-08-03T18:18:17.811Z",
"modified": "2026-06-10T15:51:12Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-35479",
"id": "EUVD-2026-35479",
"published": "2026-06-09T16:03:23Z"
}
]
}