PT-2026-3445 · Quicly · Quicly
Published
2026-01-19
·
Updated
2026-02-27
·
CVE-2025-61684
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Quicly versions prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e
Description
Quicly, an implementation of the IETF QUIC protocol, is affected by a denial-of-service issue. A remote attacker can trigger an assertion failure, leading to a process crash. The issue is exploitable without authentication.
Recommendations
Update Quicly to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e or a later version.
Exploit
Fix
DoS
RCE
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Quicly