CVE-2026-34183
Last modified
CVE-2026-34183 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service. A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing PATH_CHALLENGE frames. Impact summary: A malicious remote peer can cause an unbounded memory allocation which can lead to an abnormal termination of the application acting as a QUIC client or server and a Denial of Service. A remote peer may exhaust heap memory by flooding the local QUIC stack with PATH_CHALLENGE frames. The local QUIC stack allocates a PATH_RESPONSE frame for every PATH_CHALLENGE it receives. The allocated PATH_RESPONSE frame gets freed only when the remote peer acknowledges reception of the PATH_RESPONSE frame which will not be done by a malicious peer. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue. The QUIC stack is outside of OpenSSL FIPS module boundary.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openssl | Openssl | >= 3.4.0, < 3.4.6 |
| Openssl | Openssl | >= 3.5.0, < 3.5.7 |
| Openssl | Openssl | >= 3.6.0, < 3.6.3 |
| Openssl | Openssl | 4.0.0 |
References
- https://openssl-library.org/news/secadv/20260609.txtVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-34183?
How severe is CVE-2026-34183?
How do I fix CVE-2026-34183?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-34178In Canonical LXD before 6.8, the backup import path validate…9.1
- CVE-2026-34179In Canonical LXD versions 4.12 through 6.7, the doCertificat…9.1
- CVE-2026-3418The System REST API accepts user-supplied file uploads witho…9.1
- CVE-2026-34180Issue summary: Parsing a crafted DER-encoded ASN.1 structure…7.5
- CVE-2026-34181Issue Summary: The PKCS#12 file processing fails to perform …7.4
- CVE-2026-34182Issue Summary: Cryptographic Message Services (CMS) processi…9.1
- CVE-2026-34184AlanWeb SCADA does not enforce authorization for some direct…9.1
- CVE-2026-34185AlanWeb SCADA is vulnerable to SQL Injection across most scr…8.8
- CVE-2026-34186Improper Neutralization of Special Elements used in an SQL C…8.8
- CVE-2026-34187Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2026-34188Improper Neutralization of Special Elements used in an OS Co…7.2
- CVE-2026-3419Fastify incorrectly accepts malformed `Content-Type` headers…5.3
Are you affected by CVE-2026-34183?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
