CVE-2026-11941: CWE-416 Use after free in Cloudflare Quiche
Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to a “ConnectionId” to the applications via function arguments, but the owned “ConnectionId” would be dropped at the end of those functions' scope. Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. Impact If unpatched, an application calling the affected FFI functions will dereference freed memory. The most likely outcome is undefined behavior leading to a process crash (denial of service). Depending on allocator state, the read may also return adjacent heap contents, resulting in limited information disclosure or incorrect connection identifier handling. Mitigation Users are requested to upgrade to quiche 0.29.2 which is the earliest version containing the fix for this issue.
AI Analysis
Technical Summary
Cloudflare Quiche contained two use-after-free vulnerabilities (CWE-416) in the FFI functions quiche_connection_id_iter_next and quiche_conn_retired_scid_next. These functions returned pointers to ConnectionId objects that were dropped at the end of the function scope, leading to dereferencing freed memory. This affects only applications that use these FFI functions, which are disabled by default. The vulnerabilities can cause undefined behavior such as process crashes (denial of service) or limited information disclosure depending on heap state. The issue is fixed in quiche version 0.29.2.
Potential Impact
Applications using the affected FFI functions in Cloudflare Quiche versions prior to 0.29.2 may dereference freed memory, resulting in undefined behavior. This can lead to process crashes causing denial of service, and potentially limited information disclosure or incorrect handling of connection identifiers. The impact is limited to applications that enable and use the affected FFI API, which is disabled by default.
Mitigation Recommendations
Upgrade to Cloudflare Quiche version 0.29.2 or later, which contains the fix for these use-after-free vulnerabilities. Since the FFI API is disabled by default, applications not using these functions are not affected. No additional mitigation is required if the FFI functions are not used.
CVE-2026-11941: CWE-416 Use after free in Cloudflare Quiche
Description
Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions would return a pointer to a “ConnectionId” to the applications via function arguments, but the owned “ConnectionId” would be dropped at the end of those functions' scope. Only applications using those FFI functions are affected. The FFI API is disabled by default by a build-time feature flag. Impact If unpatched, an application calling the affected FFI functions will dereference freed memory. The most likely outcome is undefined behavior leading to a process crash (denial of service). Depending on allocator state, the read may also return adjacent heap contents, resulting in limited information disclosure or incorrect connection identifier handling. Mitigation Users are requested to upgrade to quiche 0.29.2 which is the earliest version containing the fix for this issue.
CVSS v3.1
Score 5.6medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Cloudflare Quiche contained two use-after-free vulnerabilities (CWE-416) in the FFI functions quiche_connection_id_iter_next and quiche_conn_retired_scid_next. These functions returned pointers to ConnectionId objects that were dropped at the end of the function scope, leading to dereferencing freed memory. This affects only applications that use these FFI functions, which are disabled by default. The vulnerabilities can cause undefined behavior such as process crashes (denial of service) or limited information disclosure depending on heap state. The issue is fixed in quiche version 0.29.2.
Potential Impact
Applications using the affected FFI functions in Cloudflare Quiche versions prior to 0.29.2 may dereference freed memory, resulting in undefined behavior. This can lead to process crashes causing denial of service, and potentially limited information disclosure or incorrect handling of connection identifiers. The impact is limited to applications that enable and use the affected FFI API, which is disabled by default.
Mitigation Recommendations
Upgrade to Cloudflare Quiche version 0.29.2 or later, which contains the fix for these use-after-free vulnerabilities. Since the FFI API is disabled by default, applications not using these functions are not affected. No additional mitigation is required if the FFI functions are not used.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cloudflare
- Date Reserved
- 2026-06-10T20:16:34.590Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Is Cloud Service
- true
Threat ID: 6a3525f5f198dc38c112b67c
Added to database: 06/19/2026, 11:20:21 UTC
Last enriched: 06/26/2026, 13:11:10 UTC
Last updated: 08/02/2026, 07:17:55 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.