Sceawere

Vulnerability Detail

CVE-2026-84784UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

OpenSSL QUIC Resource Exhaustion Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
9h ago
Vendor
OpenSSL
Product
OpenSSL
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Issue summary: A malicious remote peer may flood the local QUIC stack with NEW_CONNECTION_ID frames by avoiding a limit check on how many connection IDs the remote QUIC stack can use. Impact summary: The local QUIC stack sends a RETIRE_CONN_ID frame for every NEW_CONNECTION_ID frame it receives. The RETIRE_CONN_ID frame is dispatched via the Control Frame Queue (CFQ). If the remote peer also withholds ACKs, then it can force the local stack to allocate ~400MB (depending on ACK delay). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: RFC 9000 sections 5.1.1 and 5.1.2 [1] describe the mechanism by which a remote peer can notify the local QUIC stack to change the destination connection ID (a.k.a. CID) the local stack uses to identify the connection at the remote peer. Each CID is associated with a sequence number. The sequence number is transmitted in NEW_CONNECTION_ID and RETIRE_CONNECTION_ID frames to identify the CID which is being either associated with a connection or retired. The remote peer sends a NEW_CONNECTION_ID frame to let the local stack know a new CID is being associated with an existing connection. The NEW_CONNECTION_ID frame carries the new CID, its sequence number, and the retire-prior-to number. The retire-prior-to identifies existing CIDs that are to be retired. The local QUIC stack must send a RETIRE_CONNECTION_ID for every destination CID whose sequence number is less than retire-prior-to. The CID becomes retired after the local stack receives an ACK for its RETIRE_CONNECTION_ID frame. Although the OpenSSL QUIC stack supports at most one destination CID for every connection, it can be tricked into processing more than one RETIRE_CONNECTION_ID frame per connection. The OpenSSL QUIC stack currently retires the destination CID as soon as it receives the NEW_CONNECTION_ID, while in fact the destination CID must be retired after an ACK for the RETIRE_CONNECTION_ID frame is received. Correcting the flawed logic also fixes the backlog growth. [1] https://datatracker.ietf.org/doc/html/rfc9000#name-issuing-connection-ids FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-29T16:17:12.810Z",
  "pubdate": "2026-09-29T16:17:12.810Z",
  "executiveSummary": "The OpenSSL QUIC stack is susceptible to a resource exhaustion vulnerability categorized as CWE-770: Allocation of Resources Without Limits or Throttling.\nThe vulnerability arises from improper validation of NEW_CONNECTION_ID frames, allowing a remote peer to trigger excessive memory allocation.\nBy continuously sending NEW_CONNECTION_ID frames without retiring existing ones correctly, an attacker can force the local QUIC stack to queue a large volume of RETIRE_CONNECTION_ID frames in the Control Frame Queue (CFQ).\nThis behavior is exacerbated if the attacker withholds ACKs, preventing the retirement of these frames and leading to a significant memory backlog, reaching approximately 400MB.\nThe vulnerability is remotely exploitable without authentication, as the stack fails to enforce limits on connection ID management as specified by RFC 9000.\nThis poses a denial-of-service risk, as the unbounded memory growth can lead to resource depletion and service instability for the OpenSSL QUIC implementation.",
  "technicalDetails": "The vulnerability resides in the OpenSSL QUIC stack's handling of NEW_CONNECTION_ID frames, as defined in RFC 9000 sections 5.1.1 and 5.1.2. The QUIC protocol allows a peer to signal the association of a new destination connection ID (CID) with an existing connection using the NEW_CONNECTION_ID frame, which includes a sequence number and a retire-prior-to field.\nRFC 9000 mandates that if a retire-prior-to value is received, the stack must issue RETIRE_CONNECTION_ID frames for any existing CIDs with sequence numbers lower than that value. These frames remain active in the system until the remote peer provides an acknowledgement (ACK), confirming the retirement of the associated CID.\nThe root cause of this vulnerability is a logic flaw in the OpenSSL QUIC implementation: the stack prematurely considers a destination CID retired upon receipt of the NEW_CONNECTION_ID frame rather than waiting for the required ACK for the corresponding RETIRE_CONNECTION_ID frame. Because the implementation lacks a mechanism to limit the number of connection IDs being processed or queued, an attacker can flood the stack with NEW_CONNECTION_ID frames.\nThe attack flow proceeds as follows: 1) The attacker initiates a QUIC connection with the vulnerable OpenSSL stack. 2) The attacker sends a high frequency of NEW_CONNECTION_ID frames. 3) Each frame triggers the creation of a RETIRE_CONNECTION_ID frame, which is placed into the Control Frame Queue (CFQ). 4) By deliberately withholding ACKs for these outgoing RETIRE_CONNECTION_ID frames, the attacker prevents the stack from clearing the queue. 5) As the stack continues to generate and store these pending frames, the memory footprint increases monotonically.\nSince the OpenSSL QUIC stack does not enforce a limit on the number of concurrent CID operations or the size of the CFQ relative to pending ACKs, this unchecked growth consumes significant system memory, eventually reaching ~400MB per connection. This memory exhaustion results from the failure to adhere to state machine requirements where the CID should only be marked as retired upon successful delivery confirmation. Exploitation requires only basic network connectivity to the QUIC endpoint, as the vulnerable logic is exercised during standard connection management phases. The inability to throttle these requests allows for a persistent and high-impact denial-of-service condition."
}
CVE-2026-84784: OpenSSL QUIC Resource Exhaustion Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere