Логотип exploitDog
bind:CVE-2025-59530
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-59530

Количество 5

Количество 5

ubuntu логотип

CVE-2025-59530

26 дней назад

quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. This requires no authentication and can be exploited during the handshake phase. This was observed in the wild with certain server implementations. quic-go needs to be able to handle misbehaving server implementations, including those that prematurely send a HANDSHAKE_DONE frame. Versions 0.49.0, 0.54.1, and 0.55.0 discard Initial keys when receiving a HANDSHAKE_DONE frame, thereby correctly handling premature HANDSHAKE_DONE frames.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-59530

26 дней назад

quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. This requires no authentication and can be exploited during the handshake phase. This was observed in the wild with certain server implementations. quic-go needs to be able to handle misbehaving server implementations, including those that prematurely send a HANDSHAKE_DONE frame. Versions 0.49.0, 0.54.1, and 0.55.0 discard Initial keys when receiving a HANDSHAKE_DONE frame, thereby correctly handling premature HANDSHAKE_DONE frames.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-59530

11 дней назад

quic-go has Client Crash Due to Premature HANDSHAKE_DONE Frame

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-59530

26 дней назад

quic-go is an implementation of the QUIC protocol in Go. In versions p ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-47m2-4cr7-mhcw

26 дней назад

quic-go: Panic occurs when queuing undecryptable packets after handshake completion

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-59530

quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. This requires no authentication and can be exploited during the handshake phase. This was observed in the wild with certain server implementations. quic-go needs to be able to handle misbehaving server implementations, including those that prematurely send a HANDSHAKE_DONE frame. Versions 0.49.0, 0.54.1, and 0.55.0 discard Initial keys when receiving a HANDSHAKE_DONE frame, thereby correctly handling premature HANDSHAKE_DONE frames.

CVSS3: 7.5
0%
Низкий
26 дней назад
nvd логотип
CVE-2025-59530

quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure, leading to a process crash. This requires no authentication and can be exploited during the handshake phase. This was observed in the wild with certain server implementations. quic-go needs to be able to handle misbehaving server implementations, including those that prematurely send a HANDSHAKE_DONE frame. Versions 0.49.0, 0.54.1, and 0.55.0 discard Initial keys when receiving a HANDSHAKE_DONE frame, thereby correctly handling premature HANDSHAKE_DONE frames.

CVSS3: 7.5
0%
Низкий
26 дней назад
msrc логотип
CVE-2025-59530

quic-go has Client Crash Due to Premature HANDSHAKE_DONE Frame

CVSS3: 7.5
0%
Низкий
11 дней назад
debian логотип
CVE-2025-59530

quic-go is an implementation of the QUIC protocol in Go. In versions p ...

CVSS3: 7.5
0%
Низкий
26 дней назад
github логотип
GHSA-47m2-4cr7-mhcw

quic-go: Panic occurs when queuing undecryptable packets after handshake completion

CVSS3: 7.5
0%
Низкий
26 дней назад

Уязвимостей на страницу