Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qxwx-hr5v-h5q4

Опубликовано: 03 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

EPSS

Процентиль: 52%
0.00715
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 7.5
redhat
3 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 7.5
nvd
3 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

msrc
27 дней назад

QUIC zero-length UDP datagrams busy-loop

CVSS3: 7.5
debian
3 месяца назад

An issue in curl\u2019s QUIC UDP receive function allows a malicious H ...

EPSS

Процентиль: 52%
0.00715
Низкий

7.5 High

CVSS3

Дефекты

CWE-835