CVE-2026-12523
Last modified
CVE-2026-12523 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each frame has a length and a payload whose length depends on the frame type. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each frame has a length and a payload whose length depends on the frame type. quiche was found to be vulnerable when parsing some frame types to pre-allocating memory based on the declared length. An attacker would not need to send the number of declared bytes to trigger this issue. In addition, quiche was found to not apply QPACK decompression limits correctly. This could allow an attacker to send specially crafted HEADERS frames that would cause more memory commitment than otherwise advertised by MAX_FIELD_SECTION_SIZE (configured by set_max_field_section_size()). Mitigation: * Users are requested to upgrade to quiche 0.29.3 which is the earliest version containing the fix for this issue. Credits: Disclosed responsibly by Sébastien Féry
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | Quiche | >= 0.1.0, < 0.29.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-12523?
How severe is CVE-2026-12523?
How do I fix CVE-2026-12523?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12517The Fediverse Embeds WordPress plugin before 1.5.8 does not …5.3
- CVE-2026-12518A local privilege escalation vulnerability in the Logitech L…8.5
- CVE-2026-12519The WNC-M14A2A LTE-M modem driver mishandles unsolicited %NO…5
- CVE-2026-1252The Events Listing Widget plugin for WordPress is vulnerable…6.4
- CVE-2026-12520The Sierra Wireless HL7800 cellular modem driver (drivers/mo…6.4
- CVE-2026-12522The HL7800 cellular modem driver's +CGCONTRDP: response hand…8.8
- CVE-2026-12525The Redux Framework WordPress plugin before 4.5.13 does not …8.8
- CVE-2026-12526The Advanced Custom Fields: Extended WordPress plugin before…8.1
- CVE-2026-12527A broken authorization boundary in the RTSP media delivery p…6
- CVE-2026-12528A flaw was found in 389 Directory Server in the __aclp__norm…5.4
- CVE-2026-12529A security vulnerability has been detected in SourceCodester…7.3
- CVE-2026-1253The Group Chat & Video Chat by AtomChat plugin for WordPress…4.3
Are you affected by CVE-2026-12523?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
