CVE-2026-34183
Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service. A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 1.05%
- CWE
- CWE-1325
- Published
- 2026-06-09
- Last modified
- 2026-06-10
Affected products
- OpenSSL OpenSSL
- OpenSSL OpenSSL
- OpenSSL OpenSSL
- OpenSSL OpenSSL
Weakness type
Related vulnerabilities
- CVE-2026-71436 — Mermaid XY Charts are vulnerable to an infinite loop DoS
- CVE-2026-18772 — Improper input validation vulnerability in Samsung Open Source rlottie allows Oversized Serialized...
- CVE-2026-54081 — veraPDF Parser DoS via PostScript Type 1 Font Programs
- CVE-2026-54080 — veraPDF Parser DoS via PostScript CMap Streams
- CVE-2026-13056 — A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM
- CVE-2026-8199 — Post-auth memory exhaustion via bitwise match expressions
- CVE-2026-6535 — Improperly Controlled Sequential Memory Allocation in Wireshark
- CVE-2026-6533 — Improperly Controlled Sequential Memory Allocation in Wireshark