CVE-2026-94450

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.5
HIGH

Description

Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected. To remediate this issue, users should upgrade to version v1.89.0 or later.

Published
September 22, 2026 9:17 PM
Last Modified
September 22, 2026 9:17 PM
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5

Weaknesses (CWE)

CWE-1284

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.