Skip to main content

Vendor archive

quic-go_project CVEs

Beta · best-effort

5 CVEs tagged to vendor quic-go_project0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-40898

Published Jun 4, 2026

quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory allocation in quic-go's HTTP/3 client and server implement…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-64702

Published Dec 11, 2025

quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory allocation through quic-go's HTTP/3 client and server impleme…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-49295

Published Jan 10, 2024

quic-go is an implementation of the QUIC protocol (RFC 9000, RFC 9001, RFC 9002) in Go. An attacker can cause its peer to run out of memory sending a large number of PATH_CHALLENG…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-46239

Published Oct 31, 2023

quic-go is an implementation of the QUIC protocol in Go. Starting in version 0.37.0 and prior to version 0.37.3, by serializing an ACK frame after the CRYTPO that allows a node to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30591

Published Jul 6, 2022

quic-go through 0.27.0 allows remote attackers to cause a denial of service (CPU consumption) via a Slowloris variant in which incomplete QUIC or HTTP/3 requests are sent. This oc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1