CVE-2026-75804
Received Received - Intake

OpenSSL QUIC Connection Flow Control Bypass

Vulnerability report for CVE-2026-75804, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: OpenSSL Software Foundation

Description

Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection flow control for streams to make the QUIC stack receive ~100MB of memory instead of 768 KiB (default flow control window size). CWE: CWE-770: Allocation of Resources Without Limits or Throttling Description: The local QUIC stack advertises two flow control limits to its remote peer: stream flow control limit and connection flow control limit. The remote peer must follow both limits when transmitting stream data. Whenever the local QUIC stack receives a stream frame, it validates that the size of the received stream frame stays within flow control limits. If either limit is exceeded (stream level or connection level), then the QUIC stack must close the connection with a flow control error. The vulnerable OpenSSL QUIC stack enforces the stream-level but not the connection-level limit. To exploit the issue, three conditions must be met: - the remote peer opens several streams - each stream must stay within the stream-level flow control limit - there must be no zero-offset byte sent on any of the streams (to prevent the vulnerable QUIC stack from consuming data). By meeting the conditions above, the remote peer may make the local stack allocate 2 x MAX_STREAMS x (stream flow control limit) bytes of memory. MAX_STREAMS defaults to 100, and the limit applies to both bidirectional and unidirectional streams, making it 200 in total. The default flow control window for a stream is 512kB. The remote peer may force the vulnerable QUIC stack to allocate 100MB of heap per connection. FIPS impact: no The FIPS module is not affected as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openssl openssl *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OpenSSL's QUIC stack allows a remote peer to bypass connection-level flow control limits. Normally, QUIC enforces both stream and connection flow control limits, but the vulnerable version only enforces the stream limit. By opening multiple streams and sending data within stream limits without sending zero-offset bytes, a remote peer can force the local stack to allocate excessive memory (~100MB instead of the default 768 KiB).

Detection Guidance

Detecting this vulnerability requires monitoring QUIC traffic for abnormal memory usage or flow control violations. Check OpenSSL logs for QUIC-related errors or connection resets. Use network monitoring tools like Wireshark to inspect QUIC frames for excessive stream data within a single connection.

Impact Analysis

If exploited, this vulnerability could lead to denial-of-service conditions by consuming excessive memory on the affected system. It may cause performance degradation, crashes, or instability in applications using OpenSSL's QUIC implementation. Systems handling multiple QUIC connections could be particularly vulnerable.

Mitigation Strategies

Upgrade OpenSSL to the latest patched version. Disable QUIC support if not required. Implement network-level rate limiting to prevent excessive data transfer. Monitor memory usage on QUIC endpoints for unusual spikes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75804. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart