VYPR

Quiche

by Cloudflare

cargo: quiche

Source repositories

CVEs (9)

  • CVE-2026-12523HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each…

  • CVE-2025-4821HigJun 18, 2025
    risk 0.49cvss 7.5epss 0.01

    Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a…

  • CVE-2026-12707HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Section 9 of RFC 9000, which allows a single…

  • CVE-2025-7054MedAug 7, 2025
    risk 0.35cvss 6.5epss 0.00

    Cloudflare quiche was discovered to be vulnerable to an infinite loop when sending packets containing RETIRE_CONNECTION_ID frames. QUIC connections possess a set of connection identifiers (IDs); see Section 5.1 of RFC 9000 https://datatracker.ietf.org/doc/html/rfc9000#section-5…

  • CVE-2025-4820MedJun 18, 2025
    risk 0.35cvss 5.3epss 0.01

    Impact Cloudflare quiche was discovered to be vulnerable to incorrect congestion window growth, which could cause it to send data at a rate faster than the path might actually support. An unauthenticated remote attacker can exploit the vulnerability by first completing a…

  • CVE-2024-1765MedMar 12, 2024
    risk 0.31cvss 5.9epss 0.01

    Cloudflare Quiche (through version 0.19.1/0.20.0) was affected by an unlimited resource allocation vulnerability causing rapid increase of memory usage of the system running quiche server or client. A remote attacker could take advantage of this vulnerability by repeatedly…

  • CVE-2026-11941MedJun 19, 2026
    risk 0.29cvss 5.6epss 0.00

    Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to a “ConnectionId” to the applications via…

  • CVE-2023-6193MedDec 12, 2023
    risk 0.28cvss 5.3epss 0.01

    quiche v. 0.15.0 through 0.19.0 was discovered to be vulnerable to unbounded queuing of path validation messages, which could lead to excessive resource consumption. QUIC path validation (RFC 9000 Section 8.2) requires that the recipient of a PATH_CHALLENGE frame responds by…

  • CVE-2024-1410LowMar 12, 2024
    risk 0.17cvss 3.7epss 0.01

    Cloudflare quiche was discovered to be vulnerable to unbounded storage of information related to connection ID retirement, which could lead to excessive resource consumption. Each QUIC connection possesses a set of connection Identifiers (IDs); see RFC 9000 Section 5.1…