Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qxwx-hr5v-h5q4

Опубликовано: 03 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

EPSS

Процентиль: 44%
0.00577
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 7.5
redhat
около 1 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 7.5
nvd
около 1 месяца назад

An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.

CVSS3: 7.5
debian
около 1 месяца назад

An issue in curl\u2019s QUIC UDP receive function allows a malicious H ...

CVSS3: 6.5
fstec
2 месяца назад

Уязвимости функции приема UDP-пакетов QUIC библиотеки libcurl программного средства для взаимодействия с серверами cURL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 44%
0.00577
Низкий

7.5 High

CVSS3

Дефекты

CWE-835