PT-2025-50733 · Quic-Go+1 · Quic-Go+1

CVE-2025-64702

·

Publicado

2025-12-11

·

Atualizado

2026-06-05

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions quic-go versions 0.56.0 and below
Description quic-go, an implementation of the QUIC protocol in Go, is susceptible to excessive memory allocation. This occurs through the HTTP/3 client and server implementations when processing a QPACK-encoded HEADERS frame that expands into a large header field section, containing numerous unique header names and/or large values. The implementation constructs an http.Header without adequately limiting the size of the decoded header, leading to potential memory exhaustion.
Recommendations Update to version 0.57.0 or later.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CLEANSTART-2026-VJ54611
CVE-2025-64702
GHSA-G754-HX8W-X2G6
GO-2025-4233
OPENSUSE-SU-2026:10035-1
OPENSUSE-SU-2026:10131-1
OPENSUSE-SU-2026:20191-1
OPENSUSE-SU-2026:20809-1
SUSE-SU-2026:0037-1

Produtos afetados

Debian
Quic-Go