PT-2025-32266 · Cloudflare · Cloudflare Quiche

Catenacyber

·

Published

2025-08-07

·

Updated

2025-08-14

·

CVE-2025-7054

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cloudflare quiche versions 0.15.0 through 0.24.5
Description Cloudflare quiche is susceptible to an infinite loop when processing packets containing RETIRE CONNECTION ID frames. QUIC connections utilize connection identifiers (IDs) with sequence numbers to maintain synchronization between peers. An unauthenticated remote attacker can trigger this issue by sending specially crafted frames after completing a handshake, causing the victim to enter an infinite loop when attempting to send packets with RETIRE CONNECTION ID frames. This occurs due to a design feature supporting retirement across paths while maintaining connection ID synchronization.
Recommendations Cloudflare quiche versions prior to 0.24.5 are affected. Upgrade to version 0.24.5 or later to resolve this issue.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

BDU:2025-10362
CVE-2025-7054
GHSA-M3HH-F9GH-74C2

Affected Products

Cloudflare Quiche