Issue summary: OpenSSL QUIC stack does not enforce connection level flow control for streams. Remote peers may send more bytes as long as they fit within the stream flow control limits. Impact summary: A malicious remote peer may exploit the lack of connection
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-35189 | Excessive Memory Allocation in Relative CRLDP Processing | |
| CVE-2026-35191 | QUIC Unvalidated Amplification Credit may be Over Accounted | |
| CVE-2026-75806 | Unauthenticated and Undersized DTLS 1.2 AEAD Record Causes DoS | |
| CVE-2026-75805 | NULL Pointer Dereference in CMP Client Revocation Response Handling | |
| CVE-2026-42772 | Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC | |
| CVE-2026-54873 | QUIC STREAM Fragment Metadata DoS | |
| CVE-2026-54872 | Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves | |
| CVE-2026-54875 | Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V | |
| CVE-2026-77696 | Timing Side-Channel in SM2 Signature Generation | |
| CVE-2026-72897 | Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake | |
| CVE-2026-84782 | DTLS Retransmits Handshake Messages From a Stale Buffer Offset | |
| CVE-2026-84784 | QUIC: Unbounded RETIRE_CONNECTION_ID Backlog | |
| CVE-2026-84783 | Use-After-Free in X.509 Extension Cache Under Concurrent Use |
暂无评论