HIGH 8.7 NVD
CVE-2026-94450
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected.
To remediate this issue, users should upgrade to version v1.89.0 or later.
References
- https://aws.amazon.com/security/security-bulletins/2026-116-aws/
- https://github.com/aws/s2n-quic/releases/tag/v1.89.0
- https://github.com/aws/s2n-quic/security/advisories/GHSA-5rw2-6x5m-v22x
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-22 via NVD.
vulnfeed aggregates 13417 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.