MEDIUM 5.3 GitHub

CVE-2026-10740

s2n-quic has excessive memory allocation

s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a single 1200-byte packet can cause approximately 9.4 MB of allocation. By repeatedly sending such packets, the resulting memory pressure could cause denial of service. No valid handshake is required. Impacted

Affected Products

References

Published: 2026-08-14 · Source: GitHub · Feed updated: 2026-08-15
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-08-14 via GitHub. Affected: rust/s2n-quic <= 1.81.0.
vulnfeed aggregates 10939 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.