Medium severity5.3NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026
CVE-2026-10740
CVE-2026-10740
Description
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted QUIC Initial packets.
To remediate this issue, users should upgrade to v1.8.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
s2n-quiccrates.io | < 1.82.0 | 1.82.0 |
Affected products
3Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-9q54-f358-3fqfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-10740ghsaADVISORY
- aws.amazon.com/security/security-bulletins/2026-042-awsghsaWEB
- github.com/aws/s2n-quic/releases/tag/v1.82.0nvdWEB
- github.com/aws/s2n-quic/security/advisories/GHSA-9q54-f358-3fqfnvdWEB
- aws.amazon.com/security/security-bulletins/2026-042-aws/nvd
News mentions
0No linked articles in our index yet.