CVE-2026-11352
An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.71%
- CWE
- CWE-835
- Published
- 2026-07-03
- Last modified
- 2026-09-17
Affected products
- curl curl
- curl curl
- curl curl
- curl curl
Weakness type
Related vulnerabilities
- CVE-2026-24816 — Cookie Security Vulnerabilities in datavane/tis
- CVE-2026-24804 — A infinite loop vulnerability in coolsnowwolf/lede
- CVE-2026-24803 — A possible infinite loop vulnerability in coolsnowwolf/lede
- CVE-2025-55118 — BMC Control-M/Agent memory corruption in SSL/TLS communication
- CVE-2026-21905 — Junos OS: SRX Series, MX Series with MX-SPC3 or MS-MPC: Receipt of multiple specific SIP messages results in flow management process crash
- CVE-2025-7054 — Infinite loop triggered by connection ID retirement
- CVE-2025-3857 — Infinite loop condition in Amazon.IonDotnet
- CVE-2025-20253 — Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability