H2O quicly是H2O公司开源的一个 IETF QUIC 协议的实现。 H2O quicly 937d0e9之前版本存在安全漏洞,该漏洞源于CRYPTO流中有效握手消息超过32KB时触发断言失败,导致拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44436 | 7.5 HIGH | Quicly is vulnerable to connection state corruption |
| CVE-2026-44453 | 7.5 HIGH | h2o is vulnerable to musl libc stack overflow |
| CVE-2026-54340 | 7.5 HIGH | h2o has HTTP/2 state amplification |
| CVE-2026-44452 | 5.9 MEDIUM | h2o is vulnerable to heap overrun |
| CVE-2026-44433 | 5.3 MEDIUM | Quicly is vulnerable to memory exhaustion |
| CVE-2026-44434 | 5.3 MEDIUM | Quicly is vulnerable to stateless reset injection |
No comments yet