All 6 CVE vulnerabilities found in quicly, with AI-generated Chinese analysis, references, and POCs.
Vendor: h2o
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-44436 | Quicly is vulnerable to connection state corruption CWE-120 | 7.5 | High | 2026-07-16 |
| CVE-2026-44435 | Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB CWE-617 | 7.5 | High | 2026-07-16 |
| CVE-2026-44434 | Quicly is vulnerable to stateless reset injection CWE-345 | 5.3 | Medium | 2026-07-16 |
| CVE-2026-44433 | Quicly is vulnerable to memory exhaustion CWE-770 | 5.3 | Medium | 2026-07-16 |
| CVE-2025-61684 | Quicly has assertion failures CWE-20 | 7.5 | High | 2026-01-19 |
| CVE-2024-45396 | Quicly assertion failures CWE-617 | 7.5 | High | 2024-10-11 |
All 6 known CVE vulnerabilities affecting quicly with full Chinese analysis, references, and POCs where available.