JLSEC-2026-1136

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1136.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1136.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1136
Upstream
  • EUVD-2026-35479
  • GHSA-f5vx-f6jp-89j6
Published
2026-08-03T19:08:57.739Z
Modified
2026-08-03T19:20:53.755640207Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it...
Details

Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames.

Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service.

A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34183",
            "database_specific": {
                "status": "Analyzed"
            },
            "modified": "2026-07-23T08:10:00.137Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-34183",
            "imported": "2026-08-03T18:18:15.519Z",
            "id": "CVE-2026-34183",
            "published": "2026-06-09T17:17:05Z"
        },
        {
            "imported": "2026-08-03T18:19:52.623Z",
            "html_url": "https://github.com/advisories/GHSA-f5vx-f6jp-89j6",
            "modified": "2026-06-10T18:31:41Z",
            "url": "https://api.github.com/advisories/GHSA-f5vx-f6jp-89j6",
            "id": "GHSA-f5vx-f6jp-89j6",
            "published": "2026-06-09T18:30:41Z"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-35479",
            "imported": "2026-08-03T18:18:17.811Z",
            "modified": "2026-06-10T15:51:12Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-35479",
            "id": "EUVD-2026-35479",
            "published": "2026-06-09T16:03:23Z"
        }
    ]
}
References

Affected packages

Julia / AppBundler

Package

Name
AppBundler
Purl
pkg:julia/AppBundler?uuid=40eb83ae-c93a-480c-8f39-f018b568f472

Affected ranges

Type
SEMVER
Events
Introduced
1.0.0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1136.json"

Julia / OpenSSL_jll

Package

Name
OpenSSL_jll
Purl
pkg:julia/OpenSSL_jll?uuid=458c3c95-2e84-50aa-8efc-19380b2a3a95

Affected ranges

Type
SEMVER
Events
Introduced
3.5.0+0
Fixed
3.5.7+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1136.json"

Julia / Openresty_jll

Package

Name
Openresty_jll
Purl
pkg:julia/Openresty_jll?uuid=87da34d4-7b1b-5a94-8376-8cb65bf3132c

Affected ranges

Type
SEMVER
Events
Introduced
1.29.203+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1136.json"