CVE-2026-44433: CWE-770: Allocation of Resources Without Limits or Throttling in h2o quicly
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer could send a STREAM frame carrying just one byte at the largest offset being permitted to obtain additional flow control credit, which under certain circumstances could lead to a Denial of Service. Assuming the application prepares a receive buffer for storing all data that arrive out-of-order, up to the largest offset being received, this behavior could lead to the application allocating large amount of memory with the peer sending only a handful of packets, resulting in memory exhaustion. In addition to the receive buffer allocation strategy, the severity of this vulnerability depends on how the application controls the stream concurrency. In case of the H2O HTTP server, under its default setting, this bug increases the maximum amount of memory allocated per connection by about 4 times. This issue has been fixed by commit 8b178e6.
AI Analysis
Technical Summary
The vulnerability in quicly arises from improper handling of STREAM frames carrying a single byte at the largest permitted offset, which grants additional flow control credit. If the application allocates receive buffers for all out-of-order data up to the largest offset received, this can cause excessive memory allocation from minimal input, potentially exhausting memory resources. The severity depends on the application's stream concurrency controls. In H2O HTTP server's default configuration, this results in approximately a fourfold increase in maximum memory allocation per connection. The issue was fixed by commit 8b178e6, but no official remediation level or patch link is provided in the available data.
Potential Impact
This vulnerability can lead to denial of service via memory exhaustion by causing the application to allocate large amounts of memory from minimal network input. It does not impact confidentiality or integrity but affects availability. The increased memory allocation per connection can degrade server performance or cause crashes under attack conditions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The issue has been fixed in commit 8b178e6, so applying this fix or an updated version containing it is recommended once available. Until then, consider limiting stream concurrency or applying resource allocation limits if configurable in the application to reduce risk.
CVE-2026-44433: CWE-770: Allocation of Resources Without Limits or Throttling in h2o quicly
Description
Quicly is an IETF QUIC protocol implementation intended primarily for use within the H2O HTTP server. Prior to commit 8b178e6, an adversarial peer could send a STREAM frame carrying just one byte at the largest offset being permitted to obtain additional flow control credit, which under certain circumstances could lead to a Denial of Service. Assuming the application prepares a receive buffer for storing all data that arrive out-of-order, up to the largest offset being received, this behavior could lead to the application allocating large amount of memory with the peer sending only a handful of packets, resulting in memory exhaustion. In addition to the receive buffer allocation strategy, the severity of this vulnerability depends on how the application controls the stream concurrency. In case of the H2O HTTP server, under its default setting, this bug increases the maximum amount of memory allocated per connection by about 4 times. This issue has been fixed by commit 8b178e6.
CVSS v3.1
Score 5.3medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in quicly arises from improper handling of STREAM frames carrying a single byte at the largest permitted offset, which grants additional flow control credit. If the application allocates receive buffers for all out-of-order data up to the largest offset received, this can cause excessive memory allocation from minimal input, potentially exhausting memory resources. The severity depends on the application's stream concurrency controls. In H2O HTTP server's default configuration, this results in approximately a fourfold increase in maximum memory allocation per connection. The issue was fixed by commit 8b178e6, but no official remediation level or patch link is provided in the available data.
Potential Impact
This vulnerability can lead to denial of service via memory exhaustion by causing the application to allocate large amounts of memory from minimal network input. It does not impact confidentiality or integrity but affects availability. The increased memory allocation per connection can degrade server performance or cause crashes under attack conditions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The issue has been fixed in commit 8b178e6, so applying this fix or an updated version containing it is recommended once available. Until then, consider limiting stream concurrency or applying resource allocation limits if configurable in the application to reduce risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-06T14:40:00.954Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a595c2d68715ace43d0b041
Added to database: 07/16/2026, 22:33:17 UTC
Last enriched: 07/16/2026, 22:47:55 UTC
Last updated: 08/29/2026, 23:59:39 UTC
Views: 75
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.