Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead. Impact summary: An attacker
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35189 | Excessive Memory Allocation in Relative CRLDP Processing | |
| CVE-2026-35191 | QUIC Unvalidated Amplification Credit may be Over Accounted | |
| CVE-2026-75804 | QUIC Connection-Level Flow Control is Not Enforced for Streams | |
| CVE-2026-75805 | NULL Pointer Dereference in CMP Client Revocation Response Handling | |
| CVE-2026-42772 | Potential CPU DoS via O(n^2) Fragment Reassembly in QUIC | |
| CVE-2026-54873 | QUIC STREAM Fragment Metadata DoS | |
| CVE-2026-54872 | Timing Side-Channel in Scalar Multiplication for Non-NIST EC Curves | |
| CVE-2026-54875 | Non-Constant-Time SM2 Scalar Multiplication on ARM64 and RISC-V | |
| CVE-2026-77696 | Timing Side-Channel in SM2 Signature Generation | |
| CVE-2026-72897 | Out-of-Bounds Access After SSL_set_SSL_CTX() During a Handshake | |
| CVE-2026-84782 | DTLS Retransmits Handshake Messages From a Stale Buffer Offset | |
| CVE-2026-84784 | QUIC: Unbounded RETIRE_CONNECTION_ID Backlog | |
| CVE-2026-84783 | Use-After-Free in X.509 Extension Cache Under Concurrent Use |
No comments yet