h2o是H2O公司开源的一款新一代HTTP服务器。 H2O 8dc37cb之前版本存在缓冲区错误漏洞,该漏洞源于在处理TLS或QUIC的ClientHello消息时,若包含零长度的SNI扩展,服务器在复制主机名时假定其以NULL结尾,可能导致分段违规,从而引发拒绝服务攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44436 | 7.5 HIGH | Quicly is vulnerable to connection state corruption |
| CVE-2026-44435 | 7.5 HIGH | Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data e |
| CVE-2026-44453 | 7.5 HIGH | h2o is vulnerable to musl libc stack overflow |
| CVE-2026-54340 | 7.5 HIGH | h2o has HTTP/2 state amplification |
| CVE-2026-44433 | 5.3 MEDIUM | Quicly is vulnerable to memory exhaustion |
| CVE-2026-44434 | 5.3 MEDIUM | Quicly is vulnerable to stateless reset injection |
No comments yet