CVE-2026-44435
HIGHQuicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB
Title source: cnaDescription
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 937d0e9, an assertion failure is raised when the total number of valid handshake messages received over a CRYPTO stream of a single packet number space exceeds 32KB, causing a Denial of Service. This issue has been fixed by commit 937d0e9.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/h2o/quicly/security/advisories/GHSA-2cw9-5673-73gv
X_Refsource_Misc x_refsource_misc
https://github.com/h2o/quicly/commit/937d0e9e7c669fc2bee4920632ab6aaac60e4d81
Scores
CVSS v3
7.5
EPSS
0.0028
EPSS Percentile
20.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
CWE-617
Status
published
Products (1)
h2o/quicly
< 937d0e9
Published
Jul 16, 2026
Tracked Since
Jul 17, 2026